Starbleed bug threatens FPGA chipsets used at data centers, IoT devices around the world

(Image credit: Shutterstock)

Researchers have uncovered a new security bug allowing attackers to extract data by tampering with the configuration files of small integrated circuit boards found in many desktops and high-performance servers. 

The new bug, dubbed 'Starbleed', allows physical and remote access attacks on chipsets manufactured by Xilinx, resulting in the extraction of data and tampering with the files to reprogram the chip with malicious code. 

The Xilinx Field Programmable Gate Array (FPGA) chipsets are used as add-in cards on regular desktops, servers and even as standalone systems. These small integrated circuit boards run specific code programmed inside the FPGA by the device owner to suit their specific requirements. 

Starbleed

Researchers at the Horst Görtz Institute for IT Security at Ruhr-Universität Bochum and the Max Planck Institute for Security and Privacy believe that the FPGA chips are now found in several critical applications such as data centers to mobile base stations and encrypted USB sticks. 

The re-programmability of the chipsets brings the decisive advantage as users can load their own configurations that get stored and loaded in encrypted fashion from an external medium like the SRAM non-volatile memory or in the form of an external microcontroller firmware. 

The team found this vulnerability to exist in FGPA chipsets like the 7 series and the 6 series sold by Xilinx. They said the Starbleed allows attackers to crack the encrypted configurations within the chip and tamper with the operations stored inside in order to load malware. 

Christof Paar, a professor at the Max Planck Institute for Security and Privacy says there is no way to fix these issues except to replace the FPGA, given that the encryption and the bitstream mechanism work at the hardware level and require a redesign of the chip. 

On its part, Xilinx responded positively to the vulnerability that the team reported last September. The manufacturer notified customers to take steps to ensure that the threat actors did not have physical access to the FPGA components and their configuration ports. Moreover, the new generation of Xilinx UltraScale boards are not susceptible to such attacks, the team said. 

Via: Helpnetsecurity

Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring