Published Security3 min read
LoongLeak has no software fix, which turns it into a procurement problem
German researchers say Loongson's LoongArch chips leak cache data to unprivileged code. The remedies on offer are disabling hyperthreading or buying different silicon.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Researchers have identified a significant security vulnerability in processors manufactured by China's Loongson, dubbed LoongLeak, which allows attackers to potentially access sensitive data by exploiting leaky caches.
- German researchers from the Helmholtz Center for Information Security discovered that Loongson processors, which use the LoongArch instruction set architecture, have caches that leak data.
- The leakage can be exploited to extract specific information, including full-disk encryption keys and password hashes, from other applications and the operating system.
- The vulnerability can be exploited from unprivileged user space, containers, and virtual machines, potentially crossing boundaries to leak host data.
- The vulnerability is detailed on LoongLeakAttack.com.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Researchers at Germany's Helmholtz Center for Information Security have disclosed LoongLeak, a cache leakage flaw in processors from China's Loongson that use the LoongArch instruction set architecture [1][2]. What makes it worth an operator's attention is not the leak itself but the remedy list: software mitigations are not feasible, so the options are replacing hardware or disabling hyperthreading [6].
The reported capability is the kind that ends an incident review badly. According to the researchers, the leakage can be used to extract full-disk encryption keys and password hashes from other applications and from the operating system [3]. It can be exploited from unprivileged user space, from containers, and from virtual machines, in the last case potentially crossing the boundary to leak host data [4]. Details are published at LoongLeakAttack.com [5]. The brief reporting the work credits further coverage to The Register [11].
Loongson has fixed the flaw in its 3A6000 processor [7]. That is the sentence that defines the problem, because a silicon fix in one part number does nothing for the fleet you already bought. For anything not covered by that fix, the only mitigation short of replacement is switching off hyperthreading [12], which is a change you make in firmware, in a maintenance window, on every affected machine, and then live with. Reported performance impact is described as minimal [8], though on a machine where the control is turning off simultaneous multithreading, the cost is whatever your workload loses from half its logical cores.
The blast radius argument cuts both ways. Limited adoption of Loongson parts outside China may keep the population of exposed machines small [9]. Inside China, the state push for domestic technology means vulnerable devices are plausibly in public sector service, and exploitation of a cache side channel is hard to detect after the fact [10]. Cache-channel attacks do not leave the artefacts that endpoint tooling is built to find, so absence of alerts is not evidence of absence.
The practical exposure for a Western operator is inventory, not threat intelligence. If you run a subsidiary, a joint venture, a test lab, or a China-region deployment where hardware was sourced locally, the question is which SKUs actually shipped, and whether any of them host multi-tenant workloads or hold encryption keys. The VM-to-host path [4] means a LoongArch box carrying other people's guests is a different class of problem from a LoongArch box on a desk. Ask your integrator for part numbers, not architecture names.
The disclosure as reported is also thin in the places procurement needs it to be thick. The brief carries no CVE identifier and no list of affected models beyond the note that the 3A6000 is fixed [13], which leaves buyers unable to write a clean exclusion clause or a clean patch ticket.
Watch for an affected-model list and a tracking identifier from Loongson, for any Chinese public sector directive that makes hyperthreading-off mandatory on existing estates, and for whether any hosting provider running LoongArch hardware addresses the guest-to-host case [4]. Watch, too, for buyers who discover LoongArch inside appliances they never thought of as Chinese-domestic silicon.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Researchers have identified a significant security vulnerability in processors manufactured by China's Loongson, dubbed LoongLeak, which allows attackers to potentially access sensitive data by exploiting leaky caches.
- [2]
German researchers from the Helmholtz Center for Information Security discovered that Loongson processors, which use the LoongArch instruction set architecture, have caches that leak data.
- [3]
The leakage can be exploited to extract specific information, including full-disk encryption keys and password hashes, from other applications and the operating system.
- [4]
The vulnerability can be exploited from unprivileged user space, containers, and virtual machines, potentially crossing boundaries to leak host data.
- [6]
Software mitigations are not feasible for LoongLeak; mitigation requires hardware replacement or disabling hyperthreading.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC StaffAug 13Loongson processors vulnerable to LoongLeak cache attack
Additional citations
- SC World brief
- SC World brief, reporting the researchers



