ELSEIF
Your brief EB
362 stories from 101 feeds 294 clusters Refreshed 14 minutes ago next pull 20:21

SECURITY Signal 538

Domas: Bypassing memory protection with AMD's memory controllers

Illustration only Photo by Michael Dziedzic on Unsplash

Christopher Domas published a proof of concept demonstrating that AMD memory controllers' documented bank swizzle mode can bypass memory protection to read or write arbitrary data, including CPU microcode and platform security processor memory.

WHY IT MATTERS

This technique allows kernel-level code to manipulate processor instruction meanings and potentially bypass memory encryption and VM isolation. While requiring kernel privileges limits immediate exploitation, the documented behavior's unintended side-effects make it likely to be used in future attacks targeting firmware and secure processor memory.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

AMD memory controllers' bank swizzle mode can bypass memory protection to access arbitrary data including CPU microcode and platform security processor memory.

02

The behavior is documented in AMD's manual but the ability to rewrite supposedly immutable firmware without crashing appears unintentional.

03

Exploitation requires kernel-level privileges, limiting immediate risk but not eliminating future attack potential.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
LWN.net Domas: Bypassing memory protection with AMD's memory controllers Open ↗