AMD secure VM tech undone by DRAM meddling
ID: e495eb5a-6321-5735-b5cf-01d1b035d3e3
STIX ID: report--e495eb5a-6321-5735-b5cf-01d1b035d3e3
Feed Name: The Register (Security)
Threat Score
Researchers disclosed "BadRAM," an SPD (Serial Presence Detect) aliasing attack that manipulates DIMM identification to trick CPUs into creating physical memory aliases and bypass AMD SEV-SNP protections, enabling extraction of secrets from encrypted VMs; the PoC affects DDR4/DDR5, was reported to AMD (CVE-2024-21944), and can be mitigated by using SPD-locked memory, firmware updates, and physical system security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
