USENIX Security2026Top-tier venue
FABRICKED: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
Benedict Schlüter, Christoph Wech, Shweta Shinde
Abstract
Confidential computing is gaining popularity with real world cloud deployments. We present FABRICKED, a new attack that manipulates fabric routing to compromise AMD SEV-SNP. FABRICKED shows that a software adversary, by redirecting interconnect transactions, can mislead the secure co-processor to falsely initialize the system. Our primitive obtains arbitrary read and write within the victim address space, thereby violating confidentiality and integrity guarantees. FABRICKED also forges attestation reports.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4fefd20a-d09a-4c90-87ca-96c65b7e268fCited by top-tier papers3
- BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNPPhilipp Giersfeld, Benedict Schlüter, Shweta ShindeS&P 2026 · 1 citation
- STALEUS: Breaking AMD SEV-SNP via Memory IncoherenceBenedict Schlüter, Shweta ShindeUSENIX Security 2026
- DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 WritesJesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi et al.CCS 2026
Builds on20
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li et al.USENIX Security 2021 · 130 citations
- Lord of the Ring(s): Side Channel Attacks on the CPU On-Chip Ring Interconnect Are PracticalRiccardo Paccagnella, Licheng Luo, Christopher W. FletcherUSENIX Security 2021 · 121 citations
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth et al.S&P 2022 · 87 citations
- SEVurity: No Security Without Integrity : Breaking Integrity-Free Memory Encryption with Minimal AssumptionsLuca Wilke, Jan Wichelmann, Mathias Morbitzer, Thomas EisenbarthS&P 2020 · 72 citations
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi et al.USENIX Security 2024 · 48 citations
Related papers
- RMPocalypse: How a Catch-22 Breaks AMD SEV-SNPBenedict Schlüter, Shweta ShindeCCS 2025 · 1 citation
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van BulckS&P 2026 · 20 citations
- BadRAM: Practical Memory Aliasing Attacks on Trusted Execution EnvironmentsJesse De Meulemeester, Luca Wilke, David F. Oswald, Thomas Eisenbarth et al.S&P 2025
- StackWarp: Breaking AMD SEV-SNP Integrity via Deterministic Stack-Pointer Manipulation through the CPU's Stack EngineRuiyi Zhang, Tristan Hornetz, Daniel Weber, Fabian Thomas et al.USENIX Security 2026 · 1 citation
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationRobert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre SeifertCCS 2021
