Database/Firmware, BMC & network fabric
DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrink: A different read-disturbance
Impact
A different read-disturbance mechanism from Rowhammer: instead of repeatedly opening and closing a row, hold it open. That cuts the activation count needed for a flip by one to two orders of magnitude, and in the extreme a single activation of an adjacent row suffices. The operator consequence is that activation-counting mitigations - which is what essentially every deployed Rowhammer defence is - can be under threshold and still let flips through. Anything you were told about 'activations per refresh window' as a safety argument needs re-deriving.
Who can reach it
Unprivileged local code on a shared host, demonstrated on a real DDR4 system that already had Rowhammer protection enabled. Sharing a memory controller with the victim is the only requirement.
What to do
Not patchable. Mitigations have to be redesigned to bound how long a row stays open, not just how often it is activated; the authors show existing Rowhammer defences can be adapted at low additional cost, but that lands in future memory controllers and DRAM, not in your installed base. For now the honest answer to a customer asking 'is our memory isolated from the tenant next door' is no, and the only lever you control is not putting them there.
References
Related entries
- Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a WindowsNCVD-2023-001-gigabyte-uefi-firmware-oem-updat · Gigabyte UEFI firmware (OEM update-dropper in firmware)Unscored
- Intel processors with Linear Address Masking (LAM): SLAM: Linear Address Masking, a feature intended to let softwareNCVD-2023-001-intel-processors-with-linear-add · Intel processors with Linear Address Masking (LAM)Unscored
- MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing privateNCVD-2023-001-msi-intel-boot-guard-oem-key-lea · MSI / Intel Boot Guard OEM key leakUnscored
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-001-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
- Platform attestation as an operational control (fTPM vs discrete TPM trust): Design-level: on most GPU servers the TPMNCVD-2024-001-platform-attestation-as-an-opera · Platform attestation as an operational control (fTPM vs discrete TPM trust)Unscored
- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorNCVD-2024-002-intel-processors-indirect-branch · Intel processors (Indirect Branch Predictor structure)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.