Security researcher Christopher Domas has published a proof-of-concept demonstrating how a documented feature in AMD memory controllers can be manipulated to bypass standard memory protection boundaries. The accompanying technical documentation details how the “bank swizzle” mode can be reconfigured to read and write arbitrary physical memory, including regions strictly reserved for the Platform Security Processor (PSP) and CPU microcode.

Rather than exploiting a software vulnerability or patchable flaw, the technique leverages an existing hardware capability. The bank swizzle mode operates without hardware-enforced access controls to restrict its configuration. Because enabling the mode requires kernel-level privileges, an attacker with that level of system access can reconfigure the controller to override the memory isolation boundaries enforced by operating systems and hypervisors.

Operating at the memory controller level, the technique circumvents conventional software-based security models. By gaining direct access to physical memory, the method effectively bypasses memory encryption and virtual machine isolation. The disclosure illustrates how documented low-level hardware features can introduce architectural trade-offs that undermine conventional isolation mechanisms.


安全研究員 Christopher Domas 已發布概念驗證(proof-of-concept),展示如何操控 AMD 記憶體控制器中已有文件記錄的功能,以繞過標準的記憶體保護界限。隨附的技術說明文件詳述了如何重新配置「bank swizzle」模式,以讀寫任意實體記憶體,包括嚴格保留給 Platform Security Processor (PSP) 及 CPU microcode 的區域。

此技術並非利用軟件漏洞或可修補的缺陷,而是運用一項現有的硬件功能。bank swizzle 模式在運作時,並無硬件強制執行的存取控制來限制其配置。由於啟用該模式需要 kernel-level privileges,擁有該級別系統存取權限的攻擊者便可重新配置控制器,以覆寫操作系統及 hypervisor 所執行的記憶體隔離界限。

由於該技術在記憶體控制器層級運作,因此能繞過傳統軟件層面的安全模型。透過直接存取實體記憶體,此方法有效繞過記憶體加密及虛擬機器隔離。此次披露闡明了已有文件記錄的低階硬件功能,如何可能引入削弱傳統隔離機制的架構取捨。

新聞來源 / Original News Source