Source · Tier A · Peer-reviewed

DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes

J. De Meulemeester, S. Gloor, P. Jattke, D. Moghimi, D. Oswald, M. Thompson, K. Razavi, I. Verbauwhede, J. Van Bulck. 2026. 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26).

Originalhttps://ddropattack.eu/
VersionRead the authors' site and the paper PDF linked from it (https://ddropattack.eu/ddrop.pdf) on 2026-09-25. The PDF names CCS '26 (The Hague); the conference is in November 2026, and no DOI is printed. Disclosed on 2026-09-14.
Accessed2026-09-25
NoteIndependent attack paper (KU Leuven, ETH Zurich, Durham University and Google). An active DDR5 RDIMM interposer with a bill of materials of $159 injects parity errors so that cache-line writebacks are silently dropped, which the missing freshness protection in scalable memory encryption does not detect. Attacker model: brief physical access to install the interposer, plus control of host software and BIOS. Demonstrates forcing any TD into debug mode and forging attestation reports on an up-to-date Intel TDX platform, and integrity breaks of Scalable SGX and AMD SEV-SNP (no SEV-SNP attestation forgery reported). The site states that Intel and AMD consider physical attacks on DRAM out of scope for current products and issued security advisories on disclosure (AMD-SB-3048).

Cited by

Search

Full search page