One Flew over the Stack Engine's Nest: Practical Microarchitectural Attacks on the Stack Engine
Silvan Niederer, Sandro Rüegge, Ali Hajiabadi, Kaveh Razavi
Abstract
Security research on modern CPUs has raised numerous concerns in recent years.These security issues stem from classic microarchitectural optimizations designed decades ago, without consideration for security.Stack pointer tracking, also known as the stack engine in recent CPUs, is one such optimization.To investigate the security implications of the stack engine, we reverse engineer its operational details on a number of recent Intel and AMD CPUs for the first time.Our results show the particular microarchitecturedependent behaviors of the stack engine, such as the conditions under which it needs to synchronize the stack pointer values with the backend.Using these results, we build three primitives called Direct Underflow, Sync+Reload and Prime+Sync+Probe that enable information leakage through the stack engine under different conditions.We use these primitives in the construction of various covert and side-channel attacks, leaking sensitive patient records from a widely-used JSON library as an example.Our mitigation efforts reveal that recent AMD Zen 4 and Zen 5 CPUs include undocumented chicken bits which allow enabling or disabling the stack engine.Using these bits to disable the stack engine, we measure 3.98% and 3.94% slowdown using SPEC CPU2017 on Zen 4 and Zen 5, respectively, prompting the need to consider more secure designs for the stack engine in future CPUs which we also discuss. CCS Concepts• Security and privacy → Side-channel analysis and countermeasures.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8309f901-4598-4ca9-876a-6e1e2bcbc774Cited by top-tier papers1
Ask how each one uses itRelated papers
- SQUIP: Exploiting the Scheduler Queue Contention Side ChannelStefan Gast, Jonas Juffinger, Martin Schwarzl, Gururaj Saileshwar et al.S&P 2023
- Microarchitectural Leakage Templates and Their Application to Cache-Based Side ChannelsAhmad Ibrahim, Hamed Nemati, Till Schlüter, Nils Ole Tippenhauer et al.CCS 2022 · 4 citations
- FetchBench: Systematic Identification and Characterization of Proprietary PrefetchersTill Schlüter, Amit Choudhari, Lorenz Hetterich, Leon Trampert et al.CCS 2023 · 11 citations
- Don't Mesh Around: Side-Channel Attacks and Mitigations on Mesh InterconnectsMiles Dai, Riccardo Paccagnella, Miguel Gomez-Garcia, John D. McCalpin et al.USENIX Security 2022
- ExfilState: Automated Discovery of Timer-Free Cache Side Channels on ARM CPUsFabian Thomas, Michael Torres, Daniel Moghimi, Michael SchwarzCCS 2025
