News: 0001484072

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

GhostWrite Vulnerability Affects RISC-V CPU, Mitigating Takes A ~77% Performance Hit

([RISC-V] 4 Hours Ago GhostWrite Vulnerability)


Security researchers with the CISPA Helmholtz Center for Information Security have disclosed GhostWrite, a new CPU vulnerability affecting a common RISC-V processor.

While we are used to hearing about CPU vulnerabilities for x86/x86_64 and ARM, there's been less so for RISC-V in part since it hasn't been as big of a target for security researchers with less notable devices out in the market currently relying on RISC-V. But with more vendors exploring their own RISC-V chips and even more RISC-V single board computers coming to market that are more capable, it will become an increasing target for both security researchers and attackers.

The GhostWrite vulnerability allows unprivileged attackers to read/write to any part of the computer's memory and to be able to control peripheral devices like network adapters. The researchers note that the vulnerability cannot be fixed without disabling "around half of the CPU's functionality." GhostWrite comes down to an architectural bug and isn't a speculative execution vulnerability like we are so used to seeing these days.

The RISC-V CPU where the GhostWrite vulnerability was discovered is the T-Head XuanTie C910, which is found in various bare metal cloud instances like the previously reviewed [1]Scaleway EM RV1 to various Lichee devices from compute clusters to gaming consoles to laptops and various RISC-V single board computers.

The researchers believe the only way to address the GhostWrite vulnerability is disabling the vector extension of the CPU and in turn negatively impacting the performance. The researchers peg the overhead at around 77% to disabling the RISC-V vector extension support to mitigate GhostWrite.

More details on the new GhostWrite vulnerability via [2]GhostWriteAttack.com .



[1] https://www.phoronix.com/review/scaleway-risc-v-cloud

[2] https://ghostwriteattack.com/



chuckula

TemplarGR

and.elf

jindam

cynic

duby229

schmidtbag

fintux

Drizzt321

We have some absolutely irrefutable statistics to show exactly why
you are so tired.
There are not as many people actually working as you may have thought.
The population of this country is 200 million. 84 million are over
60 years of age, which leaves 116 million to do the work. People under 20
years of age total 75 million, which leaves 41 million to do the work.
There are 22 million who are employed by the government, which leaves
19 million to do the work. Four million are in the Armed Services, which
leaves 15 million to do the work. Deduct 14,800,000, the number in the state
and city offices, leaving 200,000 to do the work. There are 188,000 in
hospitals, insane asylums, etc., so that leaves 12,000 to do the work.
Now it may interest you to know that there are 11,998 people in jail,
so that leaves just 2 people to carry the load. That is you and me, and
brother, I'm getting tired of doing everything myself!