The rapid adoption of the open and extensible RISC-V instruction set architecture across diverse computing domains requires a thorough understanding of its security posture, particularly against hardware threats. While performance optimizations like speculative and out-of-order execution enhance throughput, they concurrently introduce vulnerabilities to Transient Execution Attacks (TEAs), which can bypass traditional security mechanisms. The inherent flexibility of RISC-V leads to significant microarchitectural variation among implementations, suggesting that susceptibility to TEAs is not uniform. However, systematic comparative assessments across prominent processors are still lacking. This paper addresses this gap by presenting a comparative vulnerability analysis of three widely used open-source RISC-V cores: the high performance BOOM, the reliability-oriented NOEL-V, and CVA6. We ported and evaluated a set of TEAs, including variants of Spectre and Meltdown and the most recent attacks, such as Speculative Code Store Bypass (SCSB) and Indirector. Our experiments demonstrate the successful execution of different attack subsets on each processor, revealing distinct vulnerability profiles tied to their underlying microarchitectures, offering valuable vulnerability data and practical insights that may be crucial for guiding the design of more secure processors. One of the key insights of our analysis is that, contrary to the popular belief, in-order processors are vulnerable against TEAs.
Assessing the Vulnerability of Open-Source RISC-V Processors to Transient Execution Attacks
Lazzeri, Elia;Cassano, Luca
2026-01-01
Abstract
The rapid adoption of the open and extensible RISC-V instruction set architecture across diverse computing domains requires a thorough understanding of its security posture, particularly against hardware threats. While performance optimizations like speculative and out-of-order execution enhance throughput, they concurrently introduce vulnerabilities to Transient Execution Attacks (TEAs), which can bypass traditional security mechanisms. The inherent flexibility of RISC-V leads to significant microarchitectural variation among implementations, suggesting that susceptibility to TEAs is not uniform. However, systematic comparative assessments across prominent processors are still lacking. This paper addresses this gap by presenting a comparative vulnerability analysis of three widely used open-source RISC-V cores: the high performance BOOM, the reliability-oriented NOEL-V, and CVA6. We ported and evaluated a set of TEAs, including variants of Spectre and Meltdown and the most recent attacks, such as Speculative Code Store Bypass (SCSB) and Indirector. Our experiments demonstrate the successful execution of different attack subsets on each processor, revealing distinct vulnerability profiles tied to their underlying microarchitectures, offering valuable vulnerability data and practical insights that may be crucial for guiding the design of more secure processors. One of the key insights of our analysis is that, contrary to the popular belief, in-order processors are vulnerable against TEAs.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



