TikTag: Breaking ARM's Memory Tagging Extension with Speculative Execution

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kim, Juhee, Park, Jinbum, Roh, Sihyeon, Chung, Jaeyoung, Lee, Youngjoo, Kim, Taesoo, Lee, Byoungyoung
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914833565220864
author Kim, Juhee
Park, Jinbum
Roh, Sihyeon
Chung, Jaeyoung
Lee, Youngjoo
Kim, Taesoo
Lee, Byoungyoung
author_facet Kim, Juhee
Park, Jinbum
Roh, Sihyeon
Chung, Jaeyoung
Lee, Youngjoo
Kim, Taesoo
Lee, Byoungyoung
contents ARM Memory Tagging Extension (MTE) is a new hardware feature introduced in ARMv8.5-A architecture, aiming to detect memory corruption vulnerabilities. The low overhead of MTE makes it an attractive solution to mitigate memory corruption attacks in modern software systems and is considered the most promising path forward for improving C/C++ software security. This paper explores the potential security risks posed by speculative execution attacks against MTE. Specifically, this paper identifies new TikTag gadgets capable of leaking the MTE tags from arbitrary memory addresses through speculative execution. With TikTag gadgets, attackers can bypass the probabilistic defense of MTE, increasing the attack success rate by close to 100%. We demonstrate that TikTag gadgets can be used to bypass MTE-based mitigations in real-world systems, Google Chrome and the Linux kernel. Experimental results show that TikTag gadgets can successfully leak an MTE tag with a success rate higher than 95% in less than 4 seconds. We further propose new defense mechanisms to mitigate the security risks posed by TikTag gadgets.
format Preprint
id arxiv_https___arxiv_org_abs_2406_08719
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle TikTag: Breaking ARM's Memory Tagging Extension with Speculative Execution
Kim, Juhee
Park, Jinbum
Roh, Sihyeon
Chung, Jaeyoung
Lee, Youngjoo
Kim, Taesoo
Lee, Byoungyoung
Cryptography and Security
ARM Memory Tagging Extension (MTE) is a new hardware feature introduced in ARMv8.5-A architecture, aiming to detect memory corruption vulnerabilities. The low overhead of MTE makes it an attractive solution to mitigate memory corruption attacks in modern software systems and is considered the most promising path forward for improving C/C++ software security. This paper explores the potential security risks posed by speculative execution attacks against MTE. Specifically, this paper identifies new TikTag gadgets capable of leaking the MTE tags from arbitrary memory addresses through speculative execution. With TikTag gadgets, attackers can bypass the probabilistic defense of MTE, increasing the attack success rate by close to 100%. We demonstrate that TikTag gadgets can be used to bypass MTE-based mitigations in real-world systems, Google Chrome and the Linux kernel. Experimental results show that TikTag gadgets can successfully leak an MTE tag with a success rate higher than 95% in less than 4 seconds. We further propose new defense mechanisms to mitigate the security risks posed by TikTag gadgets.
title TikTag: Breaking ARM's Memory Tagging Extension with Speculative Execution
topic Cryptography and Security
url https://arxiv.org/abs/2406.08719