CVE Feed

    Dashboard / CVE / CVE-2021-42114

    CVE-2021-42114

    Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Rowhammer access patterns, consisting of aggressors with different frequencies, phases, and amplitudes allow triggering bit flips on affected memory modules using our Blacksmith fuzzer. The patterns generated by Blacksmith were able to trigger bitflips on all 40 PC-DDR4 DRAM devices in our test pool, which cover the three major DRAM manufacturers: Samsung, SK Hynix, and Micron. This means that, even when chips advertised as Rowhammer-free are used, attackers may still be able to exploit Rowhammer. For example, this enables privilege-escalation attacks against the kernel or binaries such as the sudo binary, and also triggering bit flips in RSA-2048 keys (e.g., SSH keys) to gain cross-tenant virtual-machine access. We can confirm that DRAM devices acquired in July 2020 with DRAM chips from all three major DRAM vendors (Samsung, SK Hynix, Micron) are affected by this vulnerability. For more details, please refer to our publication.

    Published:Nov 15, 2021
    Last Modified:Nov 21, 2024
    EPS:Nov 16, 2021
    EPSS Score:0.0084
    CVSS Score:9

    Affected Products

    Vendor
    Micron
    Product
    Ddr4 Sdram
    Vendor
    Micron
    Product
    Ddr4 Sdram Firmware
    Vendor
    Micron
    Product
    Lddr4
    Vendor
    Micron
    Product
    Lddr4 Firmware
    Vendor
    Samsung
    Product
    Ddr4 Sdram
    Vendor
    Samsung
    Product
    Ddr4 Sdram Firmware
    Vendor
    Samsung
    Product
    Lddr4
    Vendor
    Samsung
    Product
    Lddr4 Firmware
    Vendor
    Skhynix
    Product
    Ddr4 Sdram
    Vendor
    Skhynix
    Product
    Ddr4 Sdram Firmware
    Vendor
    Skhynix
    Product
    Lddr4
    Vendor
    Skhynix
    Product
    Lddr4 Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High