Database/Control plane, storage & DevOps
DDR4 DRAM with in-DRAM TRR; a coupling effect that reaches rows at distance two rather than immediate neighbours
Impact
Google showed Rowhammer coupling is not confined to adjacent rows - hammering a row disturbs rows two away, and the mitigation logic that only watches immediate neighbours refreshes exactly the wrong rows. Operationally this means the TRR generation your DIMM vendor sold as a fix has a structural blind spot rather than a tuning problem, and mitigations designed around distance-one coupling need redesign. Same downstream consequences as any Rowhammer primitive: page-table corruption to host escape, or silent corruption of a co-tenant's data with no error signalled.
Who can reach it
Unprivileged local code sharing a memory controller with the victim. No CVE was assigned because this is a property of the DRAM, not a defect in a shippable product.
What to do
Nothing you can install. The industry answer is Refresh Management (RFM) in the DDR5 spec plus revised in-DRAM tracking, which means new DIMMs and a memory-controller generation that drives RFM - capex on a refresh cycle, not a patch window. In the meantime: raise the refresh rate where BIOS allows it, and treat memory-controller sharing between untrusted tenants as a policy you have chosen to accept rather than a boundary you have.
References
Related entries
- BeeGFS (client-to-metadata/storage service authentication, connAuthFile): Class entry, not a single CVE. Before BeeGFSNCVD-2022-004-beegfs-client-to-metadata-storag · BeeGFS (client-to-metadata/storage service authentication, connAuthFile)Unscored
- BeeGFS (client-to-metadata/storage service authentication, connAuthFile): Class entry, not a single CVE. Before BeeGFSNCVD-2022-005-beegfs-client-to-metadata-storag · BeeGFS (client-to-metadata/storage service authentication, connAuthFile)Unscored
- AMD - Global History Register side channel: A side channel through the branch predictor's Global History RegisterNCVD-2024-001-amd-global-history-register-side · AMD - Global History Register side channelUnscored
- AMD Zen 2, Zen 3 and Zen 4 platforms with DDR4 (7/10 Zen 2 and 6/10 Zen 3 devices flipped) and DDR5 (1/10 devices)NCVD-2024-002-amd-zen-2-zen-3-and-zen-4-platfo · AMD Zen 2, Zen 3 and Zen 4 platforms with DDR4 (7/10 Zen 2 and 6/10 Zen 3 devices flipped) and DDR5 (1/10 devices)Unscored
- AMD Zen 3 / Zen 4 - new exploitation method for SRSO (CVE-2023-20569): Google's security team demonstrated a new way toNCVD-2025-001-amd-zen-3-zen-4-new-exploitation · AMD Zen 3 / Zen 4 - new exploitation method for SRSO (CVE-2023-20569)Unscored
- AMD confidential computing - DDR5 memory bus interposition against TEEs: Compromising trusted execution environments byNCVD-2025-006-amd-confidential-computing-ddr5 · AMD confidential computing - DDR5 memory bus interposition against TEEsUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.