Researchers from Germany’s Helmholtz Center for Information Security disclosed LoongLeak, a cache leakage vulnerability affecting Loongson processors built on the LoongArch ISA. The flaw is tied to an instruction documented as leaving 32 bits of a memory register in an “uncertain” state, which the researchers found can leak data from the shared L1 data cache across applications and the operating system. Their testing showed attackers could extract sensitive information including full-disk AES keys, partial root password hashes, and data useful for defeating ASLR and stack canaries within seconds.
The researchers said exploitation is possible from unprivileged user space, containers, and guest virtual machines, enabling leakage across VM boundaries into host data. Software-only mitigations were described as insufficient, though Loongson reportedly addressed the issue in an update to its 3A6000 processor. A cache-eviction mitigation was also noted, with an estimated performance impact of up to 1.4%.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Loongson reportedly fixed the LoongLeak flaw in an update to its 3A6000 processor. The reporting also notes software-only mitigations are insufficient, and cache-eviction mitigation can impose up to a 1.4 percent performance hit.
Researchers from Germany’s Helmholtz Center for Information Security disclosed LoongLeak, a cache leakage flaw affecting Loongson processors based on the LoongArch ISA. They reported that the issue can leak L1 cache data across applications, the operating system, containers, and guest VMs, enabling recovery of sensitive material and bypasses of ASLR and stack canaries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceloongleakattack.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.