Tiktag: Breaking ARM's Memory Tagging Extension with Speculative Execution
Juhee Kim, Jinbum Park, Sihyeon Roh, Jaeyoung Chung, Youngjoo Lee, Taesoo Kim, Byoungyoung Lee
摘要
ARM Memory Tagging Extension (MTE) is a new hardware feature introduced in ARMv8.5-A architecture, aiming to detect memory corruption vulnerabilities. The low overhead of MTE makes it an attractive solution to mitigate memory corruption attacks in modern software systems and is considered the most promising path forward for improving C/C++ software security. This paper explores the potential security risks posed by speculative execution attacks against MTE. Specifically, this paper identifies new Tiktag gadgets capable of leaking the MTE tags from arbitrary memory addresses through speculative execution. With Tiktag gadgets, attackers can bypass the probabilistic defense of MTE, increasing the attack success rate by close to 100%. We demonstrate that Tiktag gadgets can be used to bypass MTE-based mitigations in real-world systems, Google Chrome and the Linux kernel. Experimental results show that Tiktag gadgets can successfully leak an MTE tag with a success rate higher than 95% in less than 4 seconds. We further propose new defense mechanisms to mitigate the security risks posed by Tiktag gadgets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- PoisonCap: Efficient Hierarchical Temporal Safety for CHERIYuecheng Wang, Jonathan Woodruff, Alfredo Mazzinghi, Peter Rugg 等CCS 2026 · 被引用 3 次
- Sharing is leaking: blocking transient-execution attacks with core-gapped confidential VMsCharly Castes, Andrew BaumannASPLOS 2024 · 被引用 2 次
- SpecASan: Mitigating Transient Execution Attacks Using Speculative Address SanitizationSaber Ganjisaffar, Esmaeil Mohmmadian Koruyeh, Jason Zellmer, Hodjat Asghari Esfeden 等ISCA 2025 · 被引用 1 次
- NanoTag: Systems Support for Efficient Byte-Granular Overflow Detection on ARM MTEMingkai Li, Hang Ye, Joseph Devietti, Suman Jana 等S&P 2026 · 被引用 1 次
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等S&P 2025
它引用的顶会 Paper22
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
- LVI: Hijacking Transient Execution through Microarchitectural Load Value InjectionJo Van Bulck, Daniel Moghimi, Michael Schwarz, Moritz Lipp 等S&P 2020 · 被引用 275 次
相关 Paper
- Sticky Tags: Efficient and Deterministic Spatial Memory Error Mitigation using Persistent Memory TagsFloris Gorter, Taddeus Kroes, Herbert Bos, Cristiano GiuffridaS&P 2024 · 被引用 22 次
- BASTAG: Byte-level Access Control on Shared Memory using ARM Memory Tagging ExtensionJunseung You, Jiwon Seo, Kyeongryong Lee, Yeongpil Cho 等CCS 2025
- MTSan: A Feasible and Practical Memory Sanitizer for Fuzzing COTS BinariesXingman Chen, Yinghao Shi, Zheyu Jiang, Yuan Li 等USENIX Security 2023
- PeTAL: Ensuring Access Control Integrity against Data-only Attacks on LinuxJuhee Kim, Jinbum Park, Yoochan Lee, Chengyu Song 等CCS 2024 · 被引用 6 次
- ARM MTE Performance in PracticeTaehyun Noh, Yingchen Wang, Tal Garfinkel, Mahesh Madhav 等USENIX Security 2026
