Database/Control plane, storage & DevOps
PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigation: Non-uniform Rowhammer patterns triggered bit flips on every one
Impact
Non-uniform Rowhammer patterns triggered bit flips on every one of the 40 DDR4 modules the researchers tested, including modules whose TRR implementation had resisted TRRespass. Scored 9.0 with a changed scope. Same operator consequence as TRRespass: an integrity attack on host memory reachable from tenant code.
Who can reach it
Local code on the node able to generate the access pattern. Scored AV:Network by the reporters because remote code paths (JavaScript, network stacks) can drive memory access, but the realistic datacenter path is a tenant workload.
What to do
No vendor patch. Use ECC and alert on correctable-error rate rather than only on uncorrectable errors; enable increased refresh rate or RFM in BIOS if your platform exposes it, accepting a small memory-bandwidth cost. Cost: BIOS change means drain and reboot. Effectively UNPATCHABLE.
References
Related entries
- Digi RealPort protocol (Digi console/terminal servers): RealPort is the protocol Digi console servers use to exposeCVE-2023-4299 · Digi RealPort protocol (Digi console/terminal servers)Critical
- Ivanti Connect Secure: Stack-based buffer overflowCVE-2025-0282 · Ivanti Connect SecureCritical
- Ivanti Connect Secure/ZTA: Stack-based buffer overflowCVE-2025-22457 · Ivanti Connect Secure/ZTACritical
- GitLab: unsanitized HTML in the CI job modal lets a developer-role user escalate privilegesCVE-2026-16627 · GitLab CE/EE (CI job modal HTML rendering)Critical
- Woodpecker CI: pipeline authors can pick any ServiceAccount for their build podsCVE-2026-61549 · Woodpecker CI Kubernetes backend (backend_options.kubernetes.serviceAccountName)Critical
- Jenkins Remoting: JEP-200 deserialization filter bypassed via fallback class resolution on the controllerCVE-2026-70426 · Jenkins Remoting (JEP-200 deserialization class filter, fallback resolution path)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.