CPU 메모리 격리를 깨는 DRAM 컨트롤러 레지스터 조작의 취약점이 발견됐다.
보안 연구자 크리스토퍼 도마스가 skitter-creek-bath-salts라는 오픈 소스 하드웨어 보안 도구를 개발했다. 이 도구는 메모리 컨트롤러 변환 레지스터를 조작하여 CPU 권한 경계를 무너뜨리고, 비권한 소프트웨어가 보호된 메모리 영역에 접근할 수 있도록 한다. 이는 현대 프로세서 아키텍처의 취약점을 드러내며 클라우드와 기밀 컴퓨팅의 보안에 영향을 미칠 수 있다.
A vulnerability in CPU memory isolation is revealed by manipulating DRAM controller registers.
Security researcher Christopher Domas developed an open-source hardware security tool called skitter-creek-bath-salts. This tool disrupts CPU privilege boundaries by manipulating memory controller translation registers, allowing unprivileged software to access protected memory regions. This reveals a significant vulnerability in modern processor architectures that could impact cloud and confidential computing security.