ÆPIC Leak: Architecturally Leaking Uninitialized Data from the Microarchitecture
Pietro Borrello, Andreas Kogler, Martin Schwarzl, Moritz Lipp, Daniel Gruss, Michael Schwarz
摘要
CPU vulnerabilities undermine the security guarantees provided by software-and hardware-security improvements. While the discovery of transient-execution attacks increased the interest in CPU vulnerabilities on a microarchitectural level, architectural CPU vulnerabilities are still understudied. In this paper, we systematically analyze existing CPU vulnerabilities showing that CPUs suffer from vulnerabilities whose root causes match with those in complex software. We show that transient-execution attacks and architectural vulnerabilities often arise from the same type of bug and identify the blank spots. Investigating the blank spots, we focus on architecturally improperly initialized data locations. We discover AEPIC Leak, the first architectural CPU bug that leaks stale data from the microarchitecture without using a side channel. AEPIC Leak works on all recent Sunny-Cove-based Intel CPUs (i.e., Ice Lake and Alder Lake). It architecturally leaks stale data incorrectly returned by reading undefined APIC-register ranges. AEPIC Leak samples data transferred between the L2 and last-level cache, including SGX enclave data, from the superqueue. We target data in use, e.g., register values and memory loads, as well as data at rest, e.g., SGX-enclave data pages. Our end-to-end attack extracts AES-NI, RSA, and even the Intel SGX attestation keys from enclaves within a few seconds. We discuss mitigations and conclude that the only short-term mitigations for AEPIC Leak are to disable APIC MMIO or not rely on SGX.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- TEE.Fail: Breaking Trusted Execution Environments via DDR5 Memory Bus InterpositionJalen Chuang, Alexander Seto, Nicolás Berrios, Stephan van Schaik 等S&P 2026 · 被引用 29 次
- ShadowLoad: Injecting State into Hardware PrefetchersLorenz Hetterich, Fabian Thomas, Lukas Gerlach, Ruiyi Zhang 等ASPLOS 2025 · 被引用 9 次
- Fides: Secure and Scalable Asynchronous DAG Consensus via Trusted ComponentsShaokang Xie, Dakai Kang, Hanzheng Lyu, Jianyu Niu 等VLDB 2026 · 被引用 8 次
- Lost and Found in Speculation: Hybrid Speculative Vulnerability DetectionMohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen 等DAC 2024 · 被引用 6 次
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks 等SIGMOD 2026 · 被引用 6 次
它引用的顶会 Paper26
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua 等S&P 2016 · 被引用 420 次
相关 Paper
- CrossTalk: Speculative Data Leaks Across Cores Are RealHany Ragab, Alyssa Milburn, Kaveh Razavi, Herbert Bos 等S&P 2021 · 被引用 162 次
- (M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side ChannelsRuiyi Zhang, Taehyun Kim, Daniel Weber, Michael SchwarzUSENIX Security 2023
- MetaLeak: Uncovering Side Channels in Secure Processor Architectures Exploiting MetadataMd Hafizul Islam Chowdhuryy, Hao Zheng, Fan YaoISCA 2024 · 被引用 3 次
- Loongleak: Architectural Cross-Privilege-Boundary Data Leakage on LoongArch CPUsLorenz Hetterich, Tristan Hornetz, Fabian Thomas, Michael SchwarzUSENIX Security 2026
- CacheOut: Leaking Data on Intel CPUs via Cache EvictionsStephan van Schaik, Marina Minkin, Andrew Kwong, Daniel Genkin 等S&P 2021 · 被引用 158 次
