DRAM controller vulnerability: accessing protected CPU regions via address translation manipulation
The skitter-creek-bath-salts project demonstrates a vulnerability in AMD Family 16h CPU DRAM controllers that allows manipulation of physical addresses in memory. This "scrambling" of DRAM enables access to protected regions such as PSP, SMM, and microcode, bypassing security mechanisms built on address translation.
How does address translation work in modern processors?
An address starts as a virtual address (VA), which the MMU translates via TLB and page tables into a physical address. This physical address then undergoes further transformations in the memory controller (interleaving, scrambling) before accessing physical DRAM.
Why is manipulating the DRAM controller dangerous?
The DRAM controller is normally used for performance optimization (interleaving, XOR scrambling), but modifying its registers can be exploited to redirect physical addresses. This allows bypassing memory isolation and accessing protected regions like SMM or PSP.
Why doesn't this vulnerability affect newer processors?
AMD stopped documenting DRAM controller registers and their locking mechanisms from the 17h series onward. Without public documentation, the technique cannot be applied to newer processors, though the physical principles remain the same.
Which security features can be bypassed?
The technique can bypass isolation of the Platform Security Processor (PSP), System Management Mode (SMM), and access to CPU microcode. All these components rely on physical memory protection, which DRAM scrambling compromises.
- DeepSeek V4 Flash on a single AMD MI300X — github.com 78 % match
- A workspace where humans and agents build together, on a relay you own. — github.com 74 % match
- Experiment with Gemma 4 as an offline translator — github.com 74 % match
- skitter-creek-bath-salts
- AMD Family 16h
- Platform Security Processor
- System Management Mode
- DRAM
- MMU
- TLB
- IOMMU
- xoreaxeaxeax