Spectre attacks still work on commercial RISC-V silicon

Researchers prove commercial RISC-V chips are still vulnerable to Spectre attacks.

CSBadmin
1 Min Read

Commercial RISC-V processors are vulnerable to all major Spectre variants, according to a paper accepted at the 35th Usenix Security Symposium. Researchers from CISPA and KU Leuven tested the SiFive P550 and T-Head Xuantie C910 and C920 and demonstrated proof-of-concept attacks using Spectre-PHT, Spectre-BTB, SpectreRSB, and Spectre-STL with up to 100% recall and over 97% precision.

The assumption that RISC-V’s simpler design makes it immune to Spectre is incorrect, the researchers found. In-order processors including the SiFive U74 and Xuantie C906 and C908 did not appear vulnerable. A proof-of-concept exploit leaked arbitrary Linux kernel memory on the Xuantie C910 at 338 bytes per second.

Software defenses developed for x86 and ARM do not necessarily transfer to RISC-V. The researchers also flag the architecture’s lack of introspection interfaces and warn that ecosystem diversity means no single mitigation will work across all systems. RISC-V inherits the software and threat model of mature architectures without their accumulated hardening, they conclude.

Findings were disclosed responsibly in December. Three patches have been merged into mainline Linux with two more under review, while SiFive has addressed P550-specific findings and T-Head has committed to publishing speculation barriers.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.