{"id":145,"date":"2025-09-02T08:50:09","date_gmt":"2025-09-02T08:50:09","guid":{"rendered":"https:\/\/haco.club\/?p=145"},"modified":"2025-09-03T08:55:27","modified_gmt":"2025-09-03T08:55:27","slug":"arbitrary-data-manipulation-and-leakage-with-cpu-zero-day-bugs-on-risc-v","status":"publish","type":"post","link":"https:\/\/haco.zone\/?p=145","title":{"rendered":"Arbitrary Data Manipulation and Leakage with CPU Zero-Day Bugs on RISC-V"},"content":{"rendered":"\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Arbitrary Data Manipulation and Leakage with CPU Zero-Day Bugs on RISC-V\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/1AAZUd_Yk7U?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"760\" src=\"https:\/\/haco.club\/wp-content\/uploads\/2025\/09\/image-1024x760.png\" alt=\"\" class=\"wp-image-146\" srcset=\"https:\/\/haco.zone\/wp-content\/uploads\/2025\/09\/image-1024x760.png 1024w, https:\/\/haco.zone\/wp-content\/uploads\/2025\/09\/image-300x223.png 300w, https:\/\/haco.zone\/wp-content\/uploads\/2025\/09\/image-768x570.png 768w, https:\/\/haco.zone\/wp-content\/uploads\/2025\/09\/image.png 1086w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Fabian Thomas and Laurent Schmierer, introduces &#8220;GhostRider,&#8221; a zero-day vulnerability they discovered in the T-Head C910 RISC-V processor. This vulnerability allows for data manipulation and leakage by bypassing software isolation and writing directly to physical memory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are the key points discussed:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>GhostRider Vulnerability:<\/strong> This exploit allows unprivileged applications to bypass operating systems and other security measures to interact directly with hardware. It exploits a flaw in a RISC-V vector instruction to write to physical memory instead of virtual memory, enabling arbitrary data manipulation, memory leakage, and privilege escalation.<\/li>\n\n\n\n<li><strong>Affected Hardware:<\/strong> The vulnerability is specific to the T-Head C910 CPU, a high-performance RISC-V processor. The issue is not with the RISC-V standard itself, but with this particular implementation.<\/li>\n\n\n\n<li><strong>Discovery:<\/strong> The researchers found this vulnerability using a method called &#8220;differential fuzzing,&#8221; where they compared the behavior of different CPUs running the same programs.<\/li>\n\n\n\n<li><strong>Mitigation:<\/strong> Since RISC-V cores lack microcode updates, the suggested solution is to disable the Vector Extension through an OS update. This, however, comes with a significant performance reduction.<\/li>\n\n\n\n<li><strong>Context:<\/strong> The talk places GhostRider in the context of other CPU vulnerabilities, highlighting its unique ability to perform unrestricted and fast memory writes.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Fabian Thomas and Laurent Schmierer, introduces &#8220;GhostRider,&#8221; a zero-day vulnerability [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[4,8,5],"class_list":["post-145","post","type-post","status-publish","format-standard","hentry","category-black-hat","tag-hardware","tag-riscv","tag-security"],"_links":{"self":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=145"}],"version-history":[{"count":3,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/145\/revisions"}],"predecessor-version":[{"id":172,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/145\/revisions\/172"}],"wp:attachment":[{"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}