Chinese Loongson CPUs found vulnerable to cache side-channel attacks

Chinese Loongson CPUs found vulnerable to cache side-channel attacks

Security researchers have uncovered vulnerabilities in Chinese Loongson processors that enable cache side-channel attacks, affecting both legacy and current chip models across multiple architectures including LoongArch and earlier designs.

The findings reveal that the cache memory implementation in Loongson processors contains structural features that can be exploited to extract sensitive information processed by other applications on the same system. These side-channel attacks leverage timing differences in cache access patterns to reconstruct confidential data.

The vulnerability spans a broad range of Loongson processors, including those based on GS464, GS464V, and the newer LoongArch instruction set architecture. Researchers emphasize that the issue is hardware-level in nature, meaning it cannot be fully remediated through software patches alone.

During their testing, the research team successfully executed cache side-channel attacks against several Loongson processor models, notably including the Loongson-3A5000 and Loongson-3A6000. The experiments demonstrated high accuracy in data extraction, with successful recovery of sensitive information across multiple test scenarios.

The researchers have notified Loongson developers about the discovered flaws, but as of now, no comprehensive fix has been released. They advise users of systems powered by these processors to exercise additional caution when handling sensitive data, particularly in multi-tenant or shared computing environments.

The findings raise particular concerns given the widespread adoption of Loongson processors in Chinese government and military systems, where security is paramount. However, the researchers note that successful exploitation requires local access to the target device, which significantly reduces the risk of remote attacks.

The research adds Loongson to a growing list of processor vendors facing side-channel vulnerability disclosures, following similar findings in Intel, AMD, and ARM chips over the past years. The full details of the research methodology and affected processor versions are expected to be presented at an upcoming security conference.

Tags: Hardware
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate