{"id":635732,"date":"2026-08-13T21:48:23","date_gmt":"2026-08-13T21:48:23","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/635732\/"},"modified":"2026-08-13T21:48:23","modified_gmt":"2026-08-13T21:48:23","slug":"chinese-loongson-cpus-expose-sensitive-l1-cache-data","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/635732\/","title":{"rendered":"Chinese Loongson CPUs Expose Sensitive L1 Cache Data"},"content":{"rendered":"<p>                    Researchers Leaked Root Password Data, Stack Canaries and AES Keys<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/tiffany-wang-i-7880\" rel=\"nofollow noopener\" target=\"_blank\">Tiffany Wang<\/a>                                                     \u2022<br \/>\n                        August 13, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/chinese-loongson-cpus-expose-sensitive-l1-cache-data-a-32551#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/08\/chinese-loongson-cpus-expose-sensitive-l1-cache-data-image_large-10-a-32551.jpg\" alt=\"Chinese Loongson CPUs Expose Sensitive L1 Cache Data\" class=\"img-responsive \"\/><\/p>\n<p>A leading CPU in used in Chinese domestic computers can leak cache data from applications and operating systems due to a flaw in the chip designer&#8217;s custom architecture, researchers found.<\/p>\n<p><b>See Also:<\/b> <a href=\"https:\/\/www.bankinfosecurity.com\/open-weight-model-antares-delivers-stronger-code-security-a-32429?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Open-Weight Model Antares Delivers Stronger Code Security<\/a><\/p>\n<p>Processors made by Loongson Technology run on a proprietary instruction set architecture called LoongArch &#8211; an interface that tells software how it can communicate with and control CPUs &#8211; that can expose up to 28 bytes of cache and leave it floating around in an &#8220;uncertain&#8221; state, <a href=\"https:\/\/loongleakattack.com\/\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> researchers from Germany&#8217;s Helmholtz Center for Information Security.<\/p>\n<p>The vulnerability, dubbed LoongLeak, allows an unprivileged attacker to leak data level-1 cache, which sits the closest to the execution units of a computer for fast retrieval of the most critical and frequently used information, researchers said. Data from multiple applications and the operating system can be stored in one cache at the same time.<\/p>\n<p>&#8220;While x86-64, Arm, and RISC-V CPUs have received significant scrutiny, Loongson processors, which are built on the LoongArch ISA and are widely used in Chinese infrastructure, have not,&#8221; <a href=\"https:\/\/loongleakattack.com\/loongleak_usenix26.pdf\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> Helmholtz Center&#8217;s Lorenz Hetterich, Tristan Hornetz, Fabian Thomas and Michael Schwarz in a paper. &#8220;This lack of analysis leaves a critical blind spot in global security, especially as China phases out foreign CPUs.&#8221;<\/p>\n<p>Since its spin-off from a research project in 2010, Loongson Technology has become a major player in China&#8217;s effort to build domestic alternatives to Intel and AMD processors. It has shipped more than 1 million units of its flagship 3A6000 desktop processor, South China Morning Post <a href=\"https:\/\/www.scmp.com\/tech\/tech-trends\/article\/3353309\/loongsons-flagship-chip-hits-1-million-units-boosting-chinas-tech-self-reliance\" target=\"_blank\" rel=\"nofollow noopener\">reported<\/a> in May.<\/p>\n<p>Researchers showed different exploits of Loongson 3A5000 and 3A6000 CPUs. On 3A5000, researchers ran the open-source video processing software FFmpeg and were able to leak special values called stack canaries that are added to programs during compilation to help detect buffer overflows before they can overwrite critical stack data.<\/p>\n<p>On the 3A6000 CPU, researchers obtained the entire random salt value used for root&#8217;s password before hashing and part of the resulting password hash from the \/etc\/shadow root entry.<\/p>\n<p>&#8220;The Loongson 3A6000 CPU supports simultaneous multi-threading, meaning a single physical CPU core operates as two logical CPU cores,&#8221; researchers said. &#8220;These logical CPU cores share a single L1 data cache, allowing LoongLeak to leak data from the sibling core.&#8221; So they also ran passwd -S on another hardware thread to make the system read the Linux shadow file that stores users\u2019 password hashes and load the secret data into the CPU&#8217;s vulnerable cache.<\/p>\n<p>The stolen hash is sufficient to mount a dictionary attack, and the overall exploit is similar to what attackers can do with a hardware vulnerability called Meltdown that allows programs to steal data currently being processed on the computer, researchers said.<\/p>\n<p>In another use case, researchers extracted AES keys from the kernel that are used for disk encryption.<\/p>\n<p>Virtual machines are also vulnerable as one attacker-controlled VM can leak data such as private certificates or SSH keys from other co-located VM. &#8220;This is especially threatening in a cloud scenario where an attacker could be co-located with VMs from other customers,&#8221; researchers said.<\/p>\n<p>&#8220;While we first discovered LoongLeak with a differential fuzzer, there is also a hint in the LoongArch manual,&#8221; researchers said. &#8220;The FLD.S instruction, which loads 32 bits from memory and stores it into a floating-point register, leaves the high 32 bits of the register &#8216;uncertain&#8217;.&#8221;<\/p>\n<p>Software updates or patches cannot fix this vulnerability because the bug lies in the hardware. Researchers suggest evicting the L1 data cache by filling it with non-sensitive data. Loongson has also fixed the flaw in their latest chip production.<\/p>\n","protected":false},"excerpt":{"rendered":"Researchers Leaked Root Password Data, Stack Canaries and AES Keys Tiffany Wang \u2022 August 13, 2026 \u00a0 \u00a0&hellip;\n","protected":false},"author":2,"featured_media":635733,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[74],"tags":[268666,18,268665,19,17,268664,268663,268661,268662,82],"class_list":["post-635732","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-chinese-processors","tag-eire","tag-hardware-security","tag-ie","tag-ireland","tag-l1-cache-leak","tag-loongarch","tag-loongleak","tag-loongson-cpu-vulnerability","tag-technology"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/117090406154561062","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/635732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=635732"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/635732\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/635733"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=635732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=635732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=635732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}