DDRop: active DDR5 interposer breaks Intel TDX / AMD SEV-SNP memory freshness
The Hacker News (14 September 2026) summarises academic/industry research (KU Leuven, ETH Zurich, Durham University, Google; ACM CCS 2026) on DDRop, an active DDR5 memory-bus interposer that silently drops writes so encrypted confidential-computing memory stays stale without integrity alarms. Targets Intel TDX (including Scalable SGX) and AMD SEV-SNP as used on major clouds; researchers demonstrated stronger outcomes on Intel TDX default logical-integrity mode (mapping, plaintext debug copy, attestation forgery) and a narrower page-copy result on AMD SEV-SNP. Requires prior software control of the host plus brief physical access to fit a ~US$159-parts interposer; researchers report no evidence of in-the-wild use. Intel and AMD treat physical interposer attacks as outside published threat models; Intel indicated it does not plan a CVE for this class of attack. No simple firmware patch: durable fix needs hardware freshness; optional Intel cryptographic-integrity mode blocks some TDX variants. Wire-only pending vendor bulletins. Primary/wire: The Hacker News.
- Product
- Intel TDX / Scalable SGX; AMD SEV-SNP (cloud confidential computing on DDR5 servers)
- Versions
- n/a (hardware design / threat-model research; no CVE assigned per Intel position reported)
- Exploited in Australia?
- unknown
- Patch to
- n/a short-term: treat physical data-centre / supply-chain access as in-scope for confidential-computing threat models; prefer stronger integrity modes where available; watch Intel/AMD bulletins
Primary: The Hacker News — DDRop vs TDX / SEV-SNP (14 Sep 2026)
