Thunderhammer: Rowhammer Bitflips via PCIe and Thunderbolt (USB-C)

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Dumitru, Robert, Wan, Junpeng, Genkin, Daniel, Kennell, Rick, Dave, Tian, Yarom, Yuval
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915498903470080
author Dumitru, Robert
Wan, Junpeng
Genkin, Daniel
Kennell, Rick
Dave
Tian
Yarom, Yuval
author_facet Dumitru, Robert
Wan, Junpeng
Genkin, Daniel
Kennell, Rick
Dave
Tian
Yarom, Yuval
contents In recent years, Rowhammer has attracted significant attention from academia and industry alike. This technique, first published in 2014, flips bits in memory by repeatedly accessing neighbouring memory locations. Since its discovery, researchers have developed a substantial body of work exploiting Rowhammer and proposing countermeasures. These works demonstrate that Rowhammer can be mounted not only through native code, but also via remote code execution, such as JavaScript in browsers, and over networks. In this work, we uncover a previously unexplored Rowhammer vector. We present Thunderhammer, an attack that induces DRAM bitflips from malicious peripherals connected via PCIe or Thunderbolt (which tunnels PCIe). On modern DDR4 systems, we observe that triggering bitflips through PCIe requests requires precisely timed access patterns tailored to the target system. We design a custom device to reverse engineer critical architectural parameters that shape PCIe request scheduling, and to execute effective hammering access patterns. Leveraging this knowledge, we successfully demonstrate Rowhammer-induced bitflips in DDR4 memory modules via both PCIe slot connections and Thunderbolt ports tunnelling PCIe.
format Preprint
id arxiv_https___arxiv_org_abs_2509_11440
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Thunderhammer: Rowhammer Bitflips via PCIe and Thunderbolt (USB-C)
Dumitru, Robert
Wan, Junpeng
Genkin, Daniel
Kennell, Rick
Dave
Tian
Yarom, Yuval
Cryptography and Security
In recent years, Rowhammer has attracted significant attention from academia and industry alike. This technique, first published in 2014, flips bits in memory by repeatedly accessing neighbouring memory locations. Since its discovery, researchers have developed a substantial body of work exploiting Rowhammer and proposing countermeasures. These works demonstrate that Rowhammer can be mounted not only through native code, but also via remote code execution, such as JavaScript in browsers, and over networks. In this work, we uncover a previously unexplored Rowhammer vector. We present Thunderhammer, an attack that induces DRAM bitflips from malicious peripherals connected via PCIe or Thunderbolt (which tunnels PCIe). On modern DDR4 systems, we observe that triggering bitflips through PCIe requests requires precisely timed access patterns tailored to the target system. We design a custom device to reverse engineer critical architectural parameters that shape PCIe request scheduling, and to execute effective hammering access patterns. Leveraging this knowledge, we successfully demonstrate Rowhammer-induced bitflips in DDR4 memory modules via both PCIe slot connections and Thunderbolt ports tunnelling PCIe.
title Thunderhammer: Rowhammer Bitflips via PCIe and Thunderbolt (USB-C)
topic Cryptography and Security
url https://arxiv.org/abs/2509.11440