Database/Control plane, storage & DevOps

SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12): Rowhammer bit flips on DDR5, which had been assumed out
Impact
Rowhammer bit flips on DDR5, which had been assumed out of reach because of on-die ECC and improved TRR. Affects SK Hynix DDR5 DIMMs produced between January 2021 and December 2024 - a very large share of DDR5 installed in AI host nodes bought in that window. Impact is integrity of host memory, with the usual escalation to privilege via page-table corruption.
Who can reach it
Local attacker on the node. High attack complexity, low privileges - a tenant workload with sustained memory access is the model.
What to do
Take an inventory of DIMM vendor and date code across the fleet (dmidecode -t memory) before anything else, because the exposure is specific. Mitigation guidance is to raise the DRAM refresh rate - tripling it substantially raises the bar at a measurable memory-bandwidth cost - which is a BIOS-level change requiring drain and reboot per node. There is no microcode or OS patch. Monitor correctable ECC error rates as the detection signal.
References
Related entries
- AMD Zen 5 RDSEED (16-bit and 32-bit variants): On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far moreCVE-2025-68313 · AMD Zen 5 RDSEED (16-bit and 32-bit variants)High
- Grafana: Auth Proxy cache key collision authenticates a low-privileged user as an administratorCVE-2026-14199 · Grafana Auth Proxy authentication (identity cache key built by concatenation)High
- GitLab EE: missing authorization lets a low-privileged member change restricted project settingsCVE-2026-16494 · GitLab EE (project update endpoint authorization)High
- Grafana: alert rule marked as a server-side expression bypasses datasource query authorizationCVE-2026-17183 · Grafana (alert rule server-side expression datasource authorization)High
- GitLab: unauthenticated GraphQL mutations executed via GET through multiplex query handlingCVE-2026-19650 · GitLab CE/EE (GraphQL multiplex query handling)High
- MinIO (server-side encryption / replication): An authenticated tenant can inject SSE metadata through replicationCVE-2026-34204 · MinIO (server-side encryption / replication)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.