PT-2020-12008 · Samsung · Ddr4+1

Published

2020-03-10

·

Updated

2020-03-16

·

CVE-2020-10255

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected, specifically chips produced by SK Hynix, Micron, and Samsung.
Description The issue is related to a vulnerability in the deployment of internal mitigations against RowHammer attacks, known as Target Row Refresh (TRR), aka the TRRespass issue. To exploit this vulnerability, an attacker needs to create certain access patterns to trigger bit flips on affected memory modules, aka a Many-sided RowHammer attack. This allows attackers to conduct privilege-escalation attacks against the kernel, conduct privilege-escalation attacks against the Sudo binary, and achieve cross-tenant virtual-machine access by corrupting RSA keys.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10255

Affected Products

Ddr4
Lpddr4