Domas: Bypassing memory protection with AMD's memory controllers
Christopher Domas has published a proof of concept with a description showing how to use AMD memory controllers' bank swizzle mode to bypass memory protection and read or write arbitrary data, including CPU microcode definitions and memory belonging to the platform security processor . Among other things, this allows code running at the kernel level to directly manipulate the meaning of processor…
Christopher Domas has unveiled a proof of concept that demonstrates how to circumvent memory protection using AMD's memory controllers and bank swizzle mode. This technique allows unauthorized access to read and write arbitrary data, including CPU microcode definitions and memory allocated to the platform security processor. Consequently, this could enable kernel-level code to manipulate the meaning of processor instructions, potentially undermining security measures such as memory encryption and virtual machine isolation.
Although this behavior is documented in AMD's manual (page 113 of the relevant PDF), the fact that it can be used to manipulate supposedly immutable parts of a computer's firmware without causing the host machine to crash appears to be an unintended consequence of the design. The vulnerability is mitigated by the fact that enabling bank swizzle mode requires kernel-level privileges, which are not typically accessible by most software.
Nonetheless, it is expected that this technique will eventually be exploited for malicious purposes.
Written by urgent.news from LWN's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.