Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors
Lukas Gerlach, Marton Bognar, Daniel Weber, Michael Schwarz, Jo Van Bulck
摘要
Speculative execution attacks have been extensively studied on mainstream x86 and ARM architectures. However, on RISC-V, research has mostly concentrated on open-source academic designs. Commercially available RISC-V silicon is widely perceived as too simple to be vulnerable, and as a result, no end-to-end attacks have been demonstrated on real hardware to date and essential software such as the Linux kernel remains unmitigated.
In this paper, we challenge that assumption. We systematically assess all commercially available out-of-order RISC-V processors (SiFive P550 and T-Head Xuantie C910/C920), finding them vulnerable to a range of Spectre attacks, and demonstrate the first Spectre attack leaking arbitrary kernel memory on real RISC-V hardware. Concerningly, our analysis reveals that mitigations in compilers, operating systems, and applications remain largely absent, and that the RISC-V instruction set lacks a dedicated speculation barrier. As a stopgap solution, we empirically characterize which instructions can halt speculation on commercial processors. We additionally audit the Linux kernel for Spectre gadgets and contribute patches, several of which have been accepted upstream. Finally, we evaluate and benchmark software-based Spectre mitigations and derive recommendations for the evolving RISC-V ecosystem, laying the groundwork for securing real hardware as it enters security-critical deployments.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper34
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- A Systematic Evaluation of Transient Execution Attacks and DefensesClaudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp 等USENIX Security 2019 · 被引用 442 次
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 被引用 357 次
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 被引用 282 次
相关 Paper
- An Analysis of Speculative Type Confusion Vulnerabilities in the WildOfek Kirzner, Adam MorrisonUSENIX Security 2021 · 被引用 40 次
- VMSCAPE: Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud EnvironmentsJean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, Kaveh RazaviS&P 2026 · 被引用 4 次
- Kasper: Scanning for Generalized Transient Execution Gadgets in the Linux KernelBrian Johannesmeyer, Jakob Koschel, Kaveh Razavi, Herbert Bos 等NDSS 2022
- SoK: Practical Foundations for Software Spectre DefensesSunjay Cauligi, Craig Disselkoen, Daniel Moghimi, Gilles Barthe 等S&P 2022 · 被引用 59 次
- A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUsLukas Gerlach, Daniel Weber, Ruiyi Zhang, Michael SchwarzS&P 2023
