Theregister
RISC-V Processors Found Vulnerable to Spectre Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers have revealed that certain commercially available RISC-V processors are vulnerable to Spectre attacks, challenging the assumption that this architecture is immune due to its simplicity. Specifically, the SiFive P550 and T-Head Xuantie C910/C920 processors can be exploited using various Spectre variants, including Spectre-PHT and Spectre-BTB. A proof-of-concept attack demonstrated the ability to leak arbitrary Linux kernel memory at a rate of 338 B/s. The study highlights a lack of mitigations in software and the absence of a dedicated speculation barrier in the RISC-V instruction set. Researchers have also contributed patches to the Linux kernel to address these vulnerabilities. The findings were presented at the 35th Usenix Security Symposium, emphasizing the need for security measures as RISC-V enters critical deployments.
Key Points: • Commercial RISC-V processors are vulnerable to Spectre attacks, contrary to prior beliefs. • Proof-of-concept exploits can leak Linux kernel memory from affected processors. • Mitigations for Spectre vulnerabilities are largely absent in the RISC-V ecosystem.