News

DDRop Breaks Intel TDX and AMD SEV-SNP Defenses

An ACM CCS 2026 paper from KU Leuven, ETH Zurich, Durham University, and Google describes DDRop, a $159 DDR5 interposer that silently drops memory writes against Intel TDX and AMD SEV-SNP. Intel and AMD say physical access sits outside their published threat models.

DDRop Breaks Intel TDX and AMD SEV-SNP Defenses

Researchers at KU Leuven, ETH Zurich, Durham University, and Google published DDRop, an ACM CCS 2026 paper on an active DDR5 RDIMM interposer that silently drops memory writes so the CPU reads stale encrypted data as if it were current. The Hacker News (Swati Khandelwal, 14 September 2026) covered the coordinated disclosure with Intel and AMD.

This is a research paper and coordinated disclosure. It is not a CISA Known Exploited Vulnerabilities listing, and it is not a CVE. Intel has said physical interposer attacks of this kind fall outside its memory-encryption protection model and it does not plan to assign a CVE. AMD says physical access attacks fall outside the published SEV/SNP threat model.

The interposer's bill of materials is about $159 for one system at a build quantity of 10, under $200. It installs in minutes, then runs from software at native DDR5 speed. The team calls it the first active interposer attack on DDR5. Earlier TEE.fail was passive, and Battering RAM was an active attack on DDR4.

DDRop exploits missing cryptographic freshness in the scalable memory encryption used by Intel TDX, Intel Scalable SGX, and AMD SEV-SNP. On Intel TDX, dropping SEPT initialization writes can produce malicious secure page tables.

Under default logical integrity, the researchers showed reading victim TD memory, forcing debug mode, and forging a launch measurement used for attestation. Stronger cryptographic integrity mode would block some cross-TD tampering. They argue attestation forge on an attacker's own TD may still apply, but their test system did not have that mode, so that path is not confirmed.

On AMD SEV-SNP the result is narrower, via the page-relocation API that can copy victim page contents. Debug-mode and attestation-forgery paths are described as TDX-specific.

Client SGX is immune because it uses a Merkle integrity tree with freshness. NVIDIA confidential GPUs keep memory in package, so an interposer cannot reach it. Arm CCA was not tested.

The researchers say they have no evidence of use outside the lab. The threat model is brief physical access (insider, supply chain, or compelled access) and then software.

There is no simple patch for the root cause. A lasting fix needs memory encryption with integrity and freshness. Software can raise the bar by restricting APIs, verifying critical writes, and detecting an interposer at boot.

This is a lab disclosure, not an observed breach of AWS, Azure, or Google Cloud confidential VMs. It still requires one physical visit to the memory bus.

Related cloud and memory tape includes exposed Vite servers leaking AWS and Azure keys, F5 BIG-IP PoisonedRefresh memory webshells, and Microsoft passkey lures into Microsoft 365 cloud theft.

Buyers of Intel TDX or AMD SEV-SNP confidential VMs should treat rack access, supply-chain integrity, and optional TDX cryptographic integrity as part of the trust story, not memory encryption alone. Ask cloud providers how they detect interposers and whether cryptographic integrity mode is available.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free