HyperHammer: Breaking Free from KVM-Enforced Isolation
Wei Chen, Zhi Zhang, Xin Zhang, Qingni Shen, Yuval Yarom, Daniel Genkin, Chen Yan, Zhe Wang
Abstract
Hardware-assisted virtualization is a key enabler of modern cloud. It decouples virtual machine execution from the hardware it runs on, allowing increased flexibility through services such as dynamic hardware provisioning and live migration. Underlying this flexibility is the security promise that guest virtual machines are isolated from each other. However, due to the level of sharing between VMs, hardware vulnerabilities present a serious threat to this usage. One such vulnerability is Rowhammer, which allows attackers to modify the contents of memory to which they have no access. While the attack has been known for over a decade, published application against such environments is limited, compromising only co-resident VMs, but not the hypervisor. Moreover, due to security concerns, a key component enabling their attack has been disabled. Hence, this attack is no longer applicable in a contemporary virtualized environment.
In this paper, we examine how Rowhammer can affect virtualized systems. We present HyperHammer, a Rowhammer attack that breaks hypervisor-enforced memory isolation
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dd4384fb-8d22-40eb-a775-92edf4302943Cited by top-tier papers3
- GeForge: Hammering GDDR Memory to Forge GPU Page Tables for Fun and ProfitJunpeng Wan, Yanan Guo, Zhi Zhang, Zhuo Li et al.S&P 2026 · 4 citations
- PRowhammer: Propagating Bit-Flips from CPU to GPUMrityunjay Shukla, Shubham Roy, Sayandeep Saha, Biswabandan PandaISCA 2026 · 1 citation
- ρHammer: Reviving RowHammer Attacks on New Architectures via PrefetchingWeijie Chen, Shan Tang, Yulin Tang, Xiapu Luo et al.MICRO 2025 · 1 citation
Builds on24
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- Drammer: Deterministic Rowhammer Attacks on Mobile PlatformsVictor van der Veen, Yanick Fratantonio, Martina Lindorfer, Daniel Gruss et al.CCS 2016 · 381 citations
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel et al.USENIX Security 2016 · 306 citations
- Another Flip in the Wall of Rowhammer DefensesDaniel Gruss, Moritz Lipp, Michael Schwarz, Daniel Genkin et al.S&P 2018 · 288 citations
- TRRespass: Exploiting the Many Sides of Target Row RefreshPietro Frigo, Emanuele Vannacci, Hasan Hassan, Victor van der Veen et al.S&P 2020 · 274 citations
Related papers
- One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege EscalationYuan Xiao, Xiaokuan Zhang, Yinqian Zhang, Radu TeodorescuUSENIX Security 2016 · 272 citations
- Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM RowhammerKevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman et al.SOSP 2023 · 13 citations
- PThammer: Cross-User-Kernel-Boundary Rowhammer through Implicit AccessesZhi Zhang, Yueqiang Cheng, Dongxi Liu, Surya Nepal et al.MICRO 2020 · 69 citations
- Quantifying Rowhammer Vulnerability for DRAM SecurityYichen Jiang, Huifeng Zhu, Dean Sullivan, Xiaolong Guo et al.DAC 2021 · 20 citations
- SledgeHammer: Amplifying Rowhammer via Bank-level ParallelismIngab Kang, Walter Wang, Jason Kim, Stephan van Schaik et al.USENIX Security 2024 · 28 citations
