logo

MTE As Implemented, Part 1: Implementation Testing

ID: 4cb5fa95-d65b-5ab0-8889-8190181000fa

STIX ID: report--4cb5fa95-d65b-5ab0-8889-8190181000fa

Feed Name: Google Project Zero

Threat Score
20/100

Date Published: 2023-08-02

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

Project Zero evaluated ARM's Memory Tagging Extensions (MTE) in hardware and Linux, finding no new speculative side-channel that leaks tag-check results but identifying multiple software and kernel implementation issues (especially with async-MTE) that enable bypasses; the report concludes that, as implemented and supported today, MTE is best viewed as a "soft" mitigation requiring kernel/application changes to improve coverage and reliability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.