Loongleak: Architectural Cross-Privilege-Boundary Data Leakage on LoongArch CPUs
Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, Michael Schwarz
摘要
Recent research has revealed architectural vulnerabilities in widely deployed CPUs that break confidentiality and integrity. While x86-64, Arm, and RISC-V CPUs have received significant scrutiny, Loongson processors, which are built on the LoongArch ISA and are widely used in Chinese infrastructure, have not. This lack of analysis leaves a critical blind spot in global security, especially as China phases out foreign CPUs.
In this paper, we discover and analyze LoongLeak, a novel architectural vulnerability affecting multiple Loongson CPUs. LoongLeak exploits how 4-byte floating-point loads return stale bytes from the L1 data cache, enabling unprivileged attackers to leak confidential data across security domains, such as the kernel or hypervisor. We demonstrate that this leakage is architectural and requires no timing or side channels, giving attackers fine-grained control over cache sets and offsets. Our case studies include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds. LoongLeak can be exploited from unprivileged user space, containers, or virtual machines. We explore software-based mitigations, including floating-point emulation, which incurs an overhead of 10 × to 21 × for floating-point heavy applications, and flushing the L1 data cache on kernel to userspace transitions in conjunction with turning off SMT threads. While these mitigations can effectively mitigate LoongLeak in software, a long-term solution requires hardware fixes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
相关 Paper
- RISCy Cache Coherence: Timer-Free Architectural Cache Attacks via Instruction/Data Cache IncoherenceFabian Thomas, Michael SchwarzS&P 2026 · 被引用 1 次
- ÆPIC Leak: Architecturally Leaking Uninitialized Data from the MicroarchitecturePietro Borrello, Andreas Kogler, Martin Schwarzl, Moritz Lipp 等USENIX Security 2022
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu 等CCS 2025
- Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order ProcessorsLukas Gerlach, Marton Bognar, Daniel Weber, Michael Schwarz 等USENIX Security 2026
- Rain: Transiently Leaking Data from Public Clouds Using Old VulnerabilitiesMathé Hertogh, Dave Quakkelaar, Thijs Raymakers, Mahesh Hari Sarma 等S&P 2026 · 被引用 5 次
