- Sources: primary, discussion
- Summary: The technique rewrites the final address translation stage in the memory controller on AMD Family 16h, the last generation whose datasheets document those DRAM controller translation registers. It reaches PSP memory, SMRAM, C6 and microcode. It presumes the attacker can already write MMIO, so it breaks the boundaries above ring 0 rather than granting ring 0.
- Why it matters: Every platform memory protection sits above the memory controller and guards physical addresses rather than DRAM coordinates, so rewriting the final translation stage reaches protected carveouts without tripping any of them.
send feedback on this story