Skip to main navigation Skip to search Skip to main content

Artifact of "Rain: Transiently Leaking Data from Public Clouds Using Old Vulnerabilities"

Dataset / Software

Description

The Rain research project shows how a malicious virtual machine can abuse transient execution vulnerabilities to leak data from the host, as well as from other virtual machines. This repository contains the research artifact: the L1TF Reloaded exploit and instructions on how to reproduce our results. It also includes the CPU/mitigation profiling code and the noise generation workloads.

For details, we refer you to:



Paper S&P'26: "Rain: Transiently Leaking Data from Public Clouds Using Old Vulnerabilities"

Project page: "Rain: Cloud Leakage via Hardware Vulnerabilities"

Disclosure to Google & AWS: "Vulnerability Disclosure Report: L1TF Reloaded"

Blog Google & us: "Project Rain:L1TF"

Blog AWS: "Amazon EC2 defenses against L1TF Reloaded"

Public disclosure WHY2025: "Spectre in the real world: Leaking your private data from the cloud with CPU vulnerabilities"

Talk Hardware.io NL 2025: "Real-World Exploitation of Transient Execution Vulnerabilities to Leak Private Data from Public Clouds"
Date made available16 Oct 2025
PublisherZenodo

Keywords

  • microarchitecture
  • security
  • Computer Security

Cite this