HomeSecurityNew ZenHammer attack affects AMD Zen processors

New ZenHammer attack affects AMD Zen processors

Academic researchers have developed ZenHammer, the first variant of the Rowhammer on DRAM memories, which works on processors based on the recent AMD Zen that maps to physical addresses in DDR4 and DDR5 memories.

See also: New Rowhammer technique bypasses DDR4 memory defenses

ZenHammer AMD Zen

AMD Zen processors and DDR5 RAM modules were previously thought to be less vulnerable to Rowhammer, so the latest findings challenge that theory.

The ZenHammer attack was developed by researchers at the public research university ETH Zurich, who shared their technical study with BleepingComputer, and it can affect AMD Zen processors.

Rowhammer is a well-documented attack method that exploits a physical feature of modern Dynamic Random-Access Memory (DRAM)to modify data by repeatedly accessing (“hammering”) specific rows of memory cells via read/write operations to change bit values.

Memory cells store information as electrical charges that determine the value of the bits within them as 1 or 0.Due to the increased density of memory cells in modern processors, repeated “hammering” can change the charge state on adjacent lines, a process known as “bit flipping.”

By strategically causing these bit changes at specific positions, an attacker could gain access to sensitive data (e.g. cryptographic keys) or escalate their privileges.

See also: PSI Software confirms ransomware attack

New ZenHammer attack affects AMD Zen processors

The technique has been implemented on Intel and ARM processors , with AMD's Zen architecture processors remaining largely unexplored, due to challenges such as unknown DRAM addressing schemes, synchronization with refresh commands, and difficulty achieving high enough line enable throughput.

With ZenHammer, researchers at the University of Zurich have managed to address these challenges by refactoring the complex and nonlinear DRAM addressing functions in AMD Zen processors.

They also evolved new synchronization techniques to synchronize attacks with DRAM refresh commands, which were critical for bypassing measures like Target Row Refresh – TRR.

Additionally, the researchers improved memory access patterns to increase row activation values, which is a critical factor in the success of Rowhammer attacks.

It is important to emphasize that these attacks are complex and successfully executing them requires an attacker with a deep understanding of both the software and hardware components.

AMD has published a security bulletin in response to ZenHammer, offering advice on mitigating the risk in AMD Zen processors and assuring that it is carefully reviewing the issues and will provide updates.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Detailed Review of the AMD RX 7600 XT Graphics Card

New ZenHammer attack affects AMD Zen processors

How do DRAM attacks work?

DRAM attacks, such as the new ZenHammer affecting AMD Zen processors, work by exploiting the physical properties of DRAM memory. DRAM stores data in cells containing a capacitor and a transistor. Each capacitor stores a bit of data as an electrical charge. However, this charge gradually leaks, requiring frequent refreshes to maintain the data bit. DRAM attacks exploit this weakness, attacking memory refresh and causing data errors. In addition to Rowhammer, another form of DRAM attack is the Cold Boot Attack, where an attacker attempts to retrieve data from DRAM after the computer. This is possible because DRAM retains data for a short time even after the power is turned off. DRAM attacks can cause serious data loss and compromise system security.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS