PT-2021-4764 · Pc-Ddr4+1 · Pc-Ddr4+1

Published

2021-11-16

·

Updated

2021-11-29

·

CVE-2021-42114

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by this issue.
Description The vulnerability is related to the internal Target Row Refresh (TRR) mitigation against Rowhammer attacks in modern DRAM devices. Novel non-uniform Rowhammer access patterns can trigger bit flips on affected memory modules, allowing attackers to exploit Rowhammer even when using chips advertised as Rowhammer-free. This enables privilege-escalation attacks against the kernel or binaries and triggering bit flips in RSA-2048 keys to gain cross-tenant virtual-machine access. All 40 PC-DDR4 DRAM devices in the test pool, covering the three major DRAM manufacturers (Samsung, SK Hynix, and Micron), are affected by this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05483
CVE-2021-42114

Affected Products

Lpddr4
Pc-Ddr4