Exploit Library
File
ddrop.pdf · 8.2 MB · click to show
ddrop.pdf · 8.2 MB · click to show
#Research
#Hardware_Security
"DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes", CCS' 2026.
]-> https://github.com/ddropattack/ddrop
// Modern TEEs such as Intel TDX, Intel Scalable SGX, and AMD SEV-SNP rely on memory encryption to protect enclaves and confidential VMs from an untrusted hypervisor or cloud operator. However, to maintain memory performance, scalable cloud TEEs omit cryptographic freshness guarantees. DDRop demonstrates active physical interposition attacks on DDR5 at native bus speeds using a custom low-cost DDR5 RDIMM interposer. By injecting parity errors on DDR5 command/address lines, the interposer silently discards cache line writebacks or swaps chip selects
4 · 270 ·