Eclipse: Preventing Speculative Memory-error Abuse with Artificial Data Dependencies
Neophytos Christou, Alexander J. Gaidis, Vaggelis Atlidakis, Vasileios P. Kemerlis
Abstract
Historically, researchers have treated memory safety-based and speculative execution attacks as two separate domains. Recent work has introduced Speculative Memory-error Abuse (SMA) attacks, which combine memory corruption vulnerabilities with Spectre-like primitives. Using SMA, an attacker can leak sensitive program information and defeat a wide variety of memory-corruption mitigations, including (K)ASLR, software-based XOM, and even ARM PA, eventually carrying out an end-to-end (architecturally-visible) exploit. We present Eclipse: a novel protection scheme against SMA attacks. Eclipse works by propagating artificial data dependencies onto sensitive data, preventing the CPU from using attacker-controlled data during speculative execution. We demonstrate that Eclipse provides comprehensive protection against speculative-probing and Pacman-style attacks, two prominent examples of Speculative Memory-error Abuse attacks that target both the x86(-64) and ARM architectures. We evaluate the performance of Eclipse on x86-64 and demonstrate that it introduces minimal overhead, compared to alternative hardening approaches, incurring ≈0%--9.5% slowdown on SPEC CPU 2017, up to 8.6% slowdown in real-world applications, and negligible overhead in the Linux kernel.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fff09dd3-f533-4e1f-9ce4-52cd147ed659Cited by top-tier papers3
- dfence: Fine-Grained Speculation Barriers for Efficient and Effective Hardware-Software Protection in the Spectre EraDavide Davoli, Marton Bognar, Lesly-Ann Daniel, Benjamin Gregoire et al.CCS 2026 · 1 citation
- The First Large-Scale Systematic Study of Python Class Pollution VulnerabilityZhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu et al.S&P 2026
- IUBIK: Isolating User Bytes in Commodity Operating System Kernels via Memory Tagging ExtensionsMarius Momeu, Alexander J. Gaidis, Jasper v. d. Heidt, Vasileios P. KemerlisS&P 2025
Builds on23
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp et al.USENIX Security 2019 · 442 citations
Related papers
- Speculative Probing: Hacking Blind in the Spectre EraEnes Göktas, Kaveh Razavi, Georgios Portokalidis, Herbert Bos et al.CCS 2020 · 36 citations
- An Analysis of Speculative Type Confusion Vulnerabilities in the WildOfek Kirzner, Adam MorrisonUSENIX Security 2021 · 40 citations
- SpecASan: Mitigating Transient Execution Attacks Using Speculative Address SanitizationSaber Ganjisaffar, Esmaeil Mohmmadian Koruyeh, Jason Zellmer, Hodjat Asghari Esfeden et al.ISCA 2025 · 1 citation
- Conditional address propagation: an efficient defense mechanism against transient execution attacksPeinan Li, Rui Hou, Lutan Zhao, Yifan Zhu et al.DAC 2022 · 1 citation
- Tiktag: Breaking ARM's Memory Tagging Extension with Speculative ExecutionJuhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung et al.S&P 2025
