USENIX Security2024Top-tier venue
SledgeHammer: Amplifying Rowhammer via Bank-level Parallelism
Ingab Kang, Walter Wang, Jason Kim, Stephan van Schaik, Youssef Tobah, Daniel Genkin, Andrew Kwong, Yuval Yarom
Abstract
Rowhammer is a hardware vulnerability in DDR memory by which attackers can perform specific access patterns in their own memory to flip bits in adjacent, uncontrolled rows without accessing them. Since its discovery by Kim et. al. (ISCA 2014), Rowhammer attacks have emerged as an alarming threat to numerous security mechanisms. In this paper, we show that Rowhammer attacks can in fact be more effective when combined with bank-level parallelism, a technique in which the attacker hammers multiple memory banks simultaneously. This allows us to increase the amount of Rowhammer-induced flips 7-fold and significantly speed up prior Rowhammer attacks relying on native code execution. Furthermore, we tackle the task of mounting browser-based Rowhammer attacks. Here, we develop a self-evicting version of multi-bank hammering, allowing us to replace clflush instructions with cache evictions. We then develop a novel method for detecting contiguous physical addresses using memory access timings, thereby obviating the need for transparent huge pages. Finally, by combining both techniques, we are the first, to our knowledge, to obtain Rowhammer bit flips on DDR4 memory from the Chrome and Firefox browsers running on default Linux configurations, without enabling transparent huge pages. ing Rowhammer attacks on DDR4, causing up to seven-fold increase in the amount of flips compared to other hammering techniques. Moreover, using multi-bank hammering we are able to demonstrate the first Rowhammer bit flips on Intel's 12th generation (Alder Lake) architecture. Finally, we show that multi-bank hammering can be performed in browser contexts, demonstrating the first Rowhammer attack in both Chrome and Firefox under default configurations, without Transparent Huge Pages (THPs). Multi-Bank Hammering. The main observation behind multi-bank Rowhammer is that while memory accesses are often written sequentially, they are actually performed in parallel when accessing different memory banks. Thus, by accessing many banks simultaneously we are essentially able to parallelize Rowhammer, improving prior works by obtaining about a 7-fold increase in the amount of bitflips found within an hour of hammering in native-code environments. Avoiding clflush. Going beyond native contexts, we next consider browser-based Rowhammer attacks. To that aim, we must avoid any use of the clflush instruction, replacing it with cache eviction techniques. Here, we introduce a new hammering technique dubbed "SledgeHammer", that leverages multi-bank hammering to improve the result of [8], traversing a set of addresses that both hammers and fully self-evicts without the use of any dummy elements. This in turn allows us to create a self-evicting Rowhammer attack without using clflush, which is required for browser-based hammering. Avoiding Transparent Huge Pages (THPs). The next step for enabling browser-based Rowhammer attacks is the need to obtain 2 MB blocks of physically contiguous memory. Not wanting to assume a non-default configuration of transparent huge pages being enabled in the kernel, we develop a novel approach for detecting physically contiguous pages using memory access timing from within the browser. This allows us to obtain the first browser-based Rowhammer attack on DDR4 memory using a fully default configuration, taking 20 seconds on average to obtain the first bit flip. Improving End-to-End Rowhammer Attacks. As a final contribution, we show how our techniques can be used to significantly improve the performance of Rowhammer. First, in the native setting we demonstrate an opcode flipping attack against the sudo binary, allowing unprivileged code to obtain root permissions within minutes. We then extend the RAMBleed [41] attack to DDR4 memory, showing a leakage rate of 1.369 bits / second. Finally, we tackle browser-based Rowhammer, obtaining flips up to 169 bits / hour, as well as demonstrating a 64-bit write primitive on Firefox. Summary of Contributions. We contribute the following: • We use bank-level parallelism to construct multi-bank hammering, and show that it can flip bits that were hitherto unflippable using prior techniques (Section 4). • We analyze the root cause behind multi-bank hammering across different Intel architectures (Section 5).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2a58db65-15bd-451b-adcc-ae83650e46deCited by top-tier papers12
- Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer DefensesF. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel et al.MICRO 2025 · 8 citations
- Memory Band-Aid: A Principled Rowhammer Defense-in-DepthCarina Fiedler, Jonas Juffinger, Sudheendra Raghav Neela, Martin Heckel et al.NDSS 2026 · 5 citations
- PVAC: A Rowhammer Mitigation Architecture Exploiting Per-Victim-Row CountingJumin Kim, Seungmin Baek, Hwayong Nam, Minbok Wi et al.ISCA 2026 · 5 citations
- GeForge: Hammering GDDR Memory to Forge GPU Page Tables for Fun and ProfitJunpeng Wan, Yanan Guo, Zhi Zhang, Zhuo Li et al.S&P 2026 · 4 citations
- FLIPPYRAM: A Large-Scale Study of Rowhammer PrevalenceMartin Heckel, Nima Sayadi, Jonas Juffinger, Carina Fiedler et al.NDSS 2026 · 2 citations
Builds on21
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss et al.CCS 2016 · 381 citations
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin et al.S&P 2018 · 288 citations
- TRRespass: Exploiting the Many Sides of Target Row RefreshPietro Frigo, Emanuele Vannacci, Hasan Hassan, Victor van der Veen et al.S&P 2020 · 274 citations
- Dedup Est Machina: Memory Deduplication as an Advanced Exploitation VectorErik Bosman, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaS&P 2016 · 252 citations
Related papers
- ρHammer: Reviving RowHammer Attacks on New Architectures via PrefetchingWeijie Chen, Shan Tang, Yulin Tang, Xiapu Luo et al.MICRO 2025 · 1 citation
- SMASH: Synchronized Many-sided Rowhammer Attacks from JavaScriptFinn de Ridder, Pietro Frigo, Emanuele Vannacci, Herbert Bos et al.USENIX Security 2021 · 124 citations
- Posthammer: Pervasive Browser-based Rowhammer Attacks with Postponed Refresh CommandsFinn de Ridder, Patrick Jattke, Kaveh RazaviUSENIX Security 2025
- Half-Double: Hammering From the Next Row OverAndreas Kogler, Jonas Juffinger, Salman Qazi, Yoongu Kim et al.USENIX Security 2022
- BlockHammer: Preventing RowHammer at Low Cost by Blacklisting Rapidly-Accessed DRAM RowsAbdullah Giray Yaglikçi, Minesh Patel, Jeremie S. Kim, Roknoddin Azizi et al.HPCA 2021 · 124 citations
