Lune

USENIX Security2026顶会

Loongleak: Architectural Cross-Privilege-Boundary Data Leakage on LoongArch CPUs

Lorenz Hetterich, Tristan Hornetz, Fabian Thomas, Michael Schwarz

出版方
2026年份

摘要

Recent research has revealed architectural vulnerabilities in widely deployed CPUs that break confidentiality and integrity. While x86-64, Arm, and RISC-V CPUs have received significant scrutiny, Loongson processors, which are built on the LoongArch ISA and are widely used in Chinese infrastructure, have not. This lack of analysis leaves a critical blind spot in global security, especially as China phases out foreign CPUs.

In this paper, we discover and analyze LoongLeak, a novel architectural vulnerability affecting multiple Loongson CPUs. LoongLeak exploits how 4-byte floating-point loads return stale bytes from the L1 data cache, enabling unprivileged attackers to leak confidential data across security domains, such as the kernel or hypervisor. We demonstrate that this leakage is architectural and requires no timing or side channels, giving attackers fine-grained control over cache sets and offsets. Our case studies include recovering full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses such as ASLR and stack canaries, all within seconds. LoongLeak can be exploited from unprivileged user space, containers, or virtual machines. We explore software-based mitigations, including floating-point emulation, which incurs an overhead of 10 × to 21 × for floating-point heavy applications, and flushing the L1 data cache on kernel to userspace transitions in conjunction with turning off SMT threads. While these mitigations can effectively mitigate LoongLeak in software, a long-term solution requires hardware fixes.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper19

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖