ON
← Back to feed
Side channel allows access to RAM of the AMD security controller PSP
Germany🏛️ PoliticsCenter9 days ago

Side channel allows access to RAM of the AMD security controller PSP

Ein Sicherheitsforscher namens Christopher Domas, bekannt unter dem Alias 'xoreaxeaxeax', hat eine Schwachstelle in älteren AMD-Prozessoren entdeckt, die als 'skitter-creek-bath-salts' bezeichnet wird. Die Forschung zeigt, dass die Abschottung von RAM-Bereichen, die für Sicherheitsfunktionen wie den AMD Platform Security Processor (PSP) reserviert sind, bei AMD-Prozessoren der Familie 16h nicht vollständig funktioniert. Dies ermöglicht potenziellen Angreifern den Zugriff auf sensible Daten, allerdings erfordert dies Admin-Rechte. Die Studie deutet darauf hin, dass ähnliche Schwachstellen in anderen CPU-Familien bestehen könnten, da AMD bei neueren Prozessoren das verwendete CPU-Register nicht mehr öffentlich dokumentiert. Betroffen sind Prozessoren aus der Bulldozer-Ära, einschließlich Modelle wie Kabini, Temash, Beema und Mullins, die ab 2013 bis 2014 produziert wurden.

A new security vulnerability has been discovered in older AMD processors, allowing unauthorized access to reserved memory areas used by critical security functions. The flaw, named “skitter-creek-bath-salts,” was identified by researcher Christopher Domas, known online as “xoreaxeaxeax.” According to his findings, this vulnerability affects AMD processors from the Family 16h series, which were introduced around 13 years ago. These processors include models such as Kabini, Temash, Beema, and Mullins, all based on the Jaguar architecture and released between 2013 and 2014. They are commonly found in budget-friendly tablets, notebooks, and embedded systems. The vulnerability exploits weaknesses in how these processors manage physical and virtual memory addresses. Specifically, it targets the DRAM controller configuration register D18F2x94, which is documented in the BIOS and Kernel Developer’s Guide (BKDG) for Family 16h models. By manipulating this register, attackers can bypass the isolation mechanisms designed to protect sensitive memory regions used by components like the AMD Platform Security Processor (PSP), System Management Mode (SMM), and CPU microcode. This allows them to read from and write to memory areas typically reserved for secure operations, including those containing cryptographic keys and other confidential data. The PSP, later renamed the AMD Secure Processor, plays a crucial role in protecting key materials used in encryption and other security features. It forms the basis for technologies like AMD Secure Encrypted Virtualization (SEV), which aims to safeguard virtual machines. However, the vulnerability reveals that even with these protections, certain memory regions remain accessible due to flaws in address management. The ARM Cortex-A5 core within the PSP uses a small portion of the installed DRAM exclusively, which is hidden from both the operating system and BIOS through the processor’s built-in memory controller. To exploit the vulnerability, attackers must manipulate the complex mapping between physical and virtual memory addresses. This requires software capable of reversing the multiple layers of address translation used in x86 architectures. The code developed by Domas demonstrates how these transformations can be reversed, effectively exposing protected memory regions. His work highlights that while the “skitter-creek-bath-salts” flaw does not directly expose the same risks as the previously known “skitter-creek-bath-salts” vulnerability, where admin rights were required to manipulate the DRAM controller, it still poses a serious threat to systems using older AMD processors. Similar attacks have targeted other hardware components, such as Intel’s Management Engine (ME), where researchers successfully accessed restricted memory areas in 2020. Another example is the BatteringRAM attack, which manipulated memory addresses to gain access to secure regions used in confidential computing. These incidents underscore the ongoing challenges in securing memory-based systems against sophisticated attacks. While AMD has documented the use of the D18F2x94 register in its BKDG, it appears that documentation for newer CPU families is less comprehensive. This lack of transparency could hinder efforts to fully assess the scope of potential vulnerabilities across different generations of AMD processors. As a result, further research is needed to determine whether similar issues exist in more recent chip designs. For now, users running systems based on the affected Family 16h processors should consider implementing additional security measures to mitigate the risk posed by this newly uncovered flaw.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 759 days ago
Side channel allows access to RAM of the AMD security controller PSP

Ein Sicherheitsforscher namens Christopher Domas, bekannt unter dem Alias 'xoreaxeaxeax', hat eine Schwachstelle in älteren AMD-Prozessoren entdeckt, die als 'skitter-creek-bath-salts' bezeichnet wird. Die Forschung zeigt, dass die Abschottung von RAM-Bereichen, die für Sicherheitsfunktionen wie den AMD Platform Security Processor (PSP) reserviert sind, bei AMD-Prozessoren der Familie 16h nicht vollständig funktioniert. Dies ermöglicht potenziellen Angreifern den Zugriff auf sensible Daten, allerdings erfordert dies Admin-Rechte. Die Studie deutet darauf hin, dass ähnliche Schwachstellen in anderen CPU-Familien bestehen könnten, da AMD bei neueren Prozessoren das verwendete CPU-Register nicht mehr öffentlich dokumentiert. Betroffen sind Prozessoren aus der Bulldozer-Ära, einschließlich Modelle wie Kabini, Temash, Beema und Mullins, die ab 2013 bis 2014 produziert wurden.

Bias read (Center): Die Berichterstattung bleibt sachlich und konzentriert sich auf technische Aspekte der Sicherheitslücke ohne politische Bewertung oder emotionale Einflussnahme. Es wird keine Seite bevorzugt, sondern lediglich Fakten über die Entdeckung und Auswirkungen der Schwachstelle präsentiert.

Why factuality (85): The article accurately describes the 'skitter-creek-bath-salts' vulnerability discovered by xoreaxeaxeax, referencing the specific AMD Family 16h processors and the associated security risks. It mentions the need for admin rights to exploit the flaw and notes that newer AMD processors no longer publ

Why objectivity (75): The article presents the findings in a generally neutral tone but uses terms like 'Lücke' (gap) and 'Gefahr' (danger) which could be seen as slightly emotive. It also frames the issue as a potential risk rather than a confirmed exploit, which may subtly influence reader perception.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories