logo

Faulty instructions in Alibaba's T-Head C910 RISC-V CPUs blow away all security

ID: eb0ff60e-61d1-51cf-8c31-13fbb5f2fa59

STIX ID: report--eb0ff60e-61d1-51cf-8c31-13fbb5f2fa59

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-08-07

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Researchers at CISPA discovered multiple architectural vulnerabilities in T-Head (Alibaba) RISC-V cores — most critically GhostWrite on the C910 — which lets unprivileged native code directly read/write physical memory and gain kernel/machine-level control; the issue is caused by a faulty non-standard vector extension implementation and requires disabling the vector extension (with major performance and compatibility impacts) as the primary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.