Unlocking _everything_ on the CPU with DRAM scrambling
Unlocking the entire CPU memory with DRAM scrambling involves modifying the DRAM controller's physical address translations. This technique is applicable to all CPU levels, including PSP, C6, microcode, SMM, and more. By altering the DRAM address translations, protected regions in memory become accessible, even those hidden from the kernel.
The project focuses on the MCT/DCT layer, where physical addresses transition into raw DRAM coordinates. A single bit change in the DRAM controller can rewire the entire memory pipeline, causing the CPU to access the wrong DRAM location. The scrambling process is relatively straightforward and can be executed with basic MMIO writes.
However, restoring the system to its original state is complex and requires precise control over memory accesses, cache states, and interrupts. The scrambling technique works across various architectures, including ARM and RISC-V. To reverse the scrambling, the DRAM controller's address transform, which is a GF(2) linear map, can be reversed using linear algebra and an SMT solver like Z3.
By identifying corresponding physical addresses in both coherent and scrambled views, the SMT solver can reconstruct the memory scrambling transformation.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.