Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization
Diego Meyer, Patrick Jattke, Michele Marazzi, Salman Qazi, Daniel Moghimi, Kaveh Razavi
Abstract
DDR5 has shown an increased resistance to Rowhammer attacks in production settings. Surprisingly, DDR5 achieves this without additional refresh management commands, pointing to the deployment of more sophisticated inDRAM Target Row Refresh (TRR) mechanisms. This paper reverse engineers such advanced TRR schemes in DDR5 devices for the first time. Our findings show that compared to older mitigations deployed in DDR4, these new schemes have considerably fewer blind spots spread over many refresh intervals. This means that an effective DDR5 Rowhammer pattern must precisely track thousands of refresh operations, which we show is not possible with existing techniques. To address this challenge, our new DDR5 Rowhammer attack, called Phoenix, self-corrects the pattern whenever it detects a missed refresh operation during the attack. Our evaluation shows that Phoenix triggers bit flips on 15 out of 15 DDR5 devices in our test pool. Using these bit flips, we build the first Rowhammer privilege escalation exploit that obtains root on a commodity DDR5 system with default settings in as little as 109 seconds. These results provide further evidence that a principled Rowhammer mitigation, such as per-row activation counters, is mandatory for a secure operation of future devices.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 03931fbb-a14a-41f9-9a4a-94276f5ab183Cited by top-tier papers8
- Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer DefensesF. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel et al.MICRO 2025 · 8 citations
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu et al.S&P 2026 · 8 citations
- DejaVu: Why You Should Write to Your DRAM Rows Twice, CarefullyHaocong Luo, Ismail Emir Yüksel, Ataberk Olgun, Nisa Bostanci et al.ISCA 2026 · 4 citations
- GeForge: Hammering GDDR Memory to Forge GPU Page Tables for Fun and ProfitJunpeng Wan, Yanan Guo, Zhi Zhang, Zhuo Li et al.S&P 2026 · 4 citations
- PRowhammer: Propagating Bit-Flips from CPU to GPUMrityunjay Shukla, Shubham Roy, Sayandeep Saha, Biswabandan PandaISCA 2026 · 1 citation
Related papers
- TRRespass: Exploiting the Many Sides of Target Row RefreshPietro Frigo, Emanuele Vannacci, Hasan Hassan, Victor van der Veen et al.S&P 2020 · 274 citations
- ZenHammer: Rowhammer Attacks on AMD Zen-based PlatformsPatrick Jattke, Max Wipfli, Flavien Solt, Michele Marazzi et al.USENIX Security 2024 · 63 citations
- BLACKSMITH: Scalable Rowhammering in the Frequency DomainPatrick Jattke, Victor van der Veen, Pietro Frigo, Stijn Gunter et al.S&P 2022 · 140 citations
- ProTRR: Principled yet Optimal In-DRAM Target Row RefreshMichele Marazzi, Patrick Jattke, Flavien Solt, Kaveh RazaviS&P 2022 · 101 citations
- PrIDE: Achieving Secure Rowhammer Mitigation with Low-Cost In-DRAM TrackersAamer Jaleel, Gururaj Saileshwar, Stephen W. Keckler, Moinuddin K. QureshiISCA 2024 · 22 citations
