DDRop: dropping DDR5 writes breaks freshness in confidential VMs on Intel TDX and AMD SEV-SNP
jedisct1 · x · 2026-09-15
Researchers disclose DDRop (ACM CCS '26, coordinated with Intel and AMD): a low-cost hardware memory interposer that silently drops DDR5 writes, making confidential VMs read stale attacker-controlled data.
- Root cause: memory encryption in Intel TDX, Scalable SGX, and AMD SEV-SNP provides confidentiality but not freshness—the CPU can verify memory is encrypted, not that it is current
- Impact: can tamper with protected VMs on both Intel and AMD platforms, and on Intel TDX can even forge the attestation evidence used to prove a VM is trusted
- Analogy: encrypted memory is a locked notebook without page numbers or dates; a dropped line still decrypts to valid-looking text
A serious hardware attack on confidential computing for shared cloud infrastructure.
More from Infra
- Prefill and Decode: why asking an LLM for three takeaways from a long document still takes minutes — dotey · 2026-09-15
- Training from scratch on a single H100 hits 76% on ARC-AGI-1 in ~4 hours — GregKamradt · 2026-09-15
- From Ollama to vLLM: a roadmap for scaling LLM deployment — kalyan_kpl · 2026-09-15
- Kimi K3 is live and free on NVIDIA NIM with OpenAI-compatible API — airesearch12 · 2026-09-15
- Dual Radeon AI Pro R9700 vs. Two Used RTX 3090s at $1600 Each for Local LLM Inference — Current-Ticket4214 · 2026-09-15
- RTX 5090 doubles to $6,899 as RAM prices eclipse GPUs in worst-ever PC build market — Yuchenj_UW · 2026-09-15