Researchers disclose LoongLeak cache flaw in Loongson processors that can leak kernel, application, and host VM data

Researchers disclosed a hardware flaw in Loongson processors that can let attackers steal sensitive data from other apps, the operating system, and even the host from inside a virtual machine. The issue, dubbed LoongLeak, stems from a LoongArch instruction that can return 32 bits in an 'uncertain' state sourced from the L1 data cache; the researchers say it can be exploited from unprivileged user space, containers, or guest virtual machines to recover secrets including full-disk AES keys, partial root password hashes, and to bypass ASLR and stack canaries. Loongson reportedly fixed the issue in an update for the 3A6000.
Why it matters: This is a serious processor-level data-leak issue because software-only defenses are limited and some attacks can cross VM boundaries. Organizations using Loongson systems should identify affected hardware, apply the available Loongson update where possible, and consider mitigation tradeoffs such as cache eviction or reduced simultaneous threading.

Sources

Chinese Loongson processors have leaky caches, researchers find
2026.08.13 100% relevant
This article appears to be the initial report in the set about the newly disclosed LoongLeak hardware vulnerability in Loongson processors.
← Back to all stories