USENIX Security2026Top-tier venue
Loongleak: Architectural Cross-Privilege-Boundary Data Leakage on LoongArch CPUs
Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, Michael Schwarz
Abstract
Recent research has revealed architectural vulnerabilities in widely deployed CPUs that break confidentiality and integrity. While x86-64, Arm, and RISC-V CPUs have received significant scrutiny, Loongson processors, which are built on the LoongArch ISA and are widely used in Chinese infrastructure, have not. This lack of analysis leaves a critical blind spot in global security, especially as China phases out foreign CPUs.
In this paper, we discover and analyze LoongLeak, a novel architectural vulnerability affecting multiple Loongson CPUs. LoongLeak exploits how 4-byte floating-point loads return stale bytes from the L1 data cache, enabling unprivileged attackers to leak confidential data across security domains, such as the kernel or hypervisor. We demonstrate that this leakage is architectural and requires no timing or side channels, giving attackers fine-grained control over cache sets and offsets. Our case studies include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds. LoongLeak can be exploited from unprivileged user space, containers, or virtual machines. We explore software-based mitigations, including floating-point emulation, which incurs an overhead of 10 × to 21 × for floating-point heavy applications, and flushing the L1 data cache on kernel to userspace transitions in conjunction with turning off SMT threads. While these mitigations can effectively mitigate LoongLeak in software, a long-term solution requires hardware fixes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6e7fba4b-ec43-4c92-b9ea-1e311a2c84b5Builds on19
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
Related papers
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 1 citation
- ÆPIC Leak: Architecturally Leaking Uninitialized Data from the MicroarchitecturePietro Borrello, Andreas Kogler, Martin Schwarzl, Moritz Lipp et al.USENIX Security 2022
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu et al.CCS 2025
- Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order ProcessorsLukas Gerlach, Marton Bognar, Daniel Weber, Michael Schwarz et al.USENIX Security 2026
- Rain: Transiently Leaking Data from Public Clouds Using Old VulnerabilitiesMathé Hertogh, Dave Quakkelaar, Thijs Raymakers, Mahesh Hari Sarma et al.S&P 2026 · 5 citations
