MTE As Implemented, Part 1: Implementation Testing
ID: 4cb5fa95-d65b-5ab0-8889-8190181000fa
STIX ID: report--4cb5fa95-d65b-5ab0-8889-8190181000fa
Feed Name: Google Project Zero
Threat Score
Project Zero evaluated ARM's Memory Tagging Extensions (MTE) in hardware and Linux, finding no new speculative side-channel that leaks tag-check results but identifying multiple software and kernel implementation issues (especially with async-MTE) that enable bypasses; the report concludes that, as implemented and supported today, MTE is best viewed as a "soft" mitigation requiring kernel/application changes to improve coverage and reliability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
