Advisory
Published 2026-09-14
Verified 2026-09-19

DDRop: active DDR5 interposer breaks Intel TDX / AMD SEV-SNP memory freshness

The Hacker News (14 September 2026) summarises academic/industry research (KU Leuven, ETH Zurich, Durham University, Google; ACM CCS 2026) on DDRop, an active DDR5 memory-bus interposer that silently drops writes so encrypted confidential-computing memory stays stale without integrity alarms. Targets Intel TDX (including Scalable SGX) and AMD SEV-SNP as used on major clouds; researchers demonstrated stronger outcomes on Intel TDX default logical-integrity mode (mapping, plaintext debug copy, attestation forgery) and a narrower page-copy result on AMD SEV-SNP. Requires prior software control of the host plus brief physical access to fit a ~US$159-parts interposer; researchers report no evidence of in-the-wild use. Intel and AMD treat physical interposer attacks as outside published threat models; Intel indicated it does not plan a CVE for this class of attack. No simple firmware patch: durable fix needs hardware freshness; optional Intel cryptographic-integrity mode blocks some TDX variants. Wire-only pending vendor bulletins. Primary/wire: The Hacker News.

Product
Intel TDX / Scalable SGX; AMD SEV-SNP (cloud confidential computing on DDR5 servers)
Versions
n/a (hardware design / threat-model research; no CVE assigned per Intel position reported)
Exploited in Australia?
unknown
Patch to
n/a short-term: treat physical data-centre / supply-chain access as in-scope for confidential-computing threat models; prefer stronger integrity modes where available; watch Intel/AMD bulletins

Primary: The Hacker News — DDRop vs TDX / SEV-SNP (14 Sep 2026)

tech cloud