Understanding and Mitigating Covert Channel and Side Channel Vulnerabilities Introduced by RowHammer Defenses
F. Nisa Bostanci, Oguzhan Canpolat, Ataberk Olgun, Ismail Emir Yüksel, Konstantinos Kanellopoulos, Mohammad Sadrosadati, Abdullah Giray Yaglikçi, Onur Mutlu
Abstract
DRAM chips are increasingly vulnerable to read disturbance phenomena (e.g., RowHammer and RowPress), where repeatedly accessing or keeping open a DRAM row causes bitflips in nearby rows, due to DRAM density scaling. Attackers can exploit RowHammer bitflips in real systems to compromise security, which has motivated many prior works on RowHammer defenses. To enable such defenses, recent DDR specifications introduce new defense frameworks (e.g., PRAC and RFM). For robust (i.e., secure, safe, and reliable) operation, it is critical to analyze security implications of widely-adopted RowHammer defenses. Yet, no prior work analyzes the timing covert channel and side channel vulnerabilities RowHammer defenses introduce.
This paper presents the first analysis and evaluation of timing covert channel and side channel vulnerabilities introduced by state-of-the-art RowHammer defenses. We demonstrate that RowHammer defenses' preventive actions (e.g., preventively refreshing potential victim rows) have two fundamental features that allow an attacker to exploit RowHammer defenses for timing leakage. First, preventive actions often reduce DRAM bandwidth availability because they block access to DRAM, thereby resulting in significantly longer memory access latencies. Second, users can intentionally trigger preventive actions because preventive actions highly depend on application memory access patterns.
We introduce LeakyHammer, a new class of attacks that leverage the RowHammer defense-induced memory latency differences to establish communication channels between processes and leak secrets from victim processes. First, we build two covert channel attacks exploiting two state-of-the-art RowHammer defenses (i.e., PRAC and RFM), achieving 39.0 Kbps and 48.7 Kbps channel capacity. Second, we demonstrate a proofof-concept website fingerprinting attack that can identify visited websites based on the RowHammer-preventive actions they cause. We propose and evaluate three countermeasures against LeakyHammer. Our results show that fundamentally and completely mitigating LeakyHammer induces large performance overheads in highly RowHammer-vulnerable systems. We believe and hope our work can enable and aid future work on designing better solutions and more robust systems in the presence of such new vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a58e6ab6-c906-47c3-af9f-ce9c51ea9374Cited by top-tier papers4
- ColumnDisturb: Understanding Column-based Read Disturbance in Real DRAM Chips and Implications for Future SystemsIsmail Emir Yuksel, Ataberk Olgun, Nisa Bostanci, Haocong Luo et al.MICRO 2025 · 15 citations
- PVAC: A Rowhammer Mitigation Architecture Exploiting Per-Victim-Row CountingJumin Kim, Seungmin Baek, Hwayong Nam, Minbok Wi et al.ISCA 2026 · 5 citations
- DejaVu: Why You Should Write to Your DRAM Rows Twice, CarefullyHaocong Luo, Ismail Emir Yüksel, Ataberk Olgun, Nisa Bostanci et al.ISCA 2026 · 4 citations
- Loaded Dice: Solving the Non-Selection Problem for Scalable Probabilistic RowHammer DefenseJeonghyun Woo, Junsu Kim, Aamer Jaleel, Prashant J. NairISCA 2026 · 1 citation
Builds on79
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem et al.NDSS 2018 · 399 citations
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss et al.CCS 2016 · 381 citations
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin et al.S&P 2018 · 288 citations
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
Related papers
- When Mitigations Backfire: Timing Channel Attacks and Defense for PRAC-Based RowHammer MitigationsJeonghyun Woo, Joyce Qu, Gururaj Saileshwar, Prashant Jayaprakash NairISCA 2025 · 6 citations
- Chronus: Understanding and Securing the Cutting-Edge Industry Solutions to DRAM Read DisturbanceOguzhan Canpolat, A. Giray Yaglikçi, Geraldo F. Oliveira, Ataberk Olgun et al.HPCA 2025 · 23 citations
- BreakHammer: Enhancing RowHammer Mitigations by Carefully Throttling Suspect ThreadsOguzhan Canpolat, A. Giray Yaglikçi, Ataberk Olgun, Ismail Emir Yuksel et al.MICRO 2024 · 19 citations
- Understanding RowHammer Under Reduced Refresh Latency: Experimental Analysis of Real DRAM Chips and Implications on Future SolutionsYahya Can Tugrul, A. Giray Yaglikçi, Ismail Emir Yüksel, Ataberk Olgun et al.HPCA 2025 · 10 citations
- BlockHammer: Preventing RowHammer at Low Cost by Blacklisting Rapidly-Accessed DRAM RowsAbdullah Giray Yaglikçi, Minesh Patel, Jeremie S. Kim, Roknoddin Azizi et al.HPCA 2021 · 124 citations
