BadRAM attack, which allows bypassing the SEV-SNP attestation mechanism in AMD CPUs

A group of researchers from the University of Leuven, the University of Lübeck, and the University of Birmingham has developed a BadRAM attack method (CVE-2024-21944) that allows bypassing the authentication mechanism and compromising environments protected by the SEV-SNP extension in AMD processors. To execute this attack, the attacker, with few exceptions, must gain physical access to the memory modules and also have the ability to execute code at ring 0 on the server running the protected guest environments.

AMD SEV (Secure Encrypted Virtualization) extensions aim to provide guarantees for the memory integrity of virtual machines, as well as to protect them from tampering and analysis by the host system administrator capable of executing code at the hypervisor level. Initially, AMD SEV protection was limited to encrypting the contents of the guest system's memory and isolating registers, but later, in AMD EPYC processors, the SEV-SNP (Secure Nested Paging) extension was implemented to safely handle nested memory page tables, ensuring memory integrity and preventing changes to the guest system's memory by the hypervisor.

The AMD SEV-SNP mechanism was created to prevent intelligence agencies or data center and cloud provider personnel, where protected guest systems operate, from interfering with the guest system's operation. The proposed BadRAM attack method allows bypassing the provided guarantees by altering the SPD (Serial Presence Detect) metadata in DDR4 or DDR5 memory modules. If the attack is successful, the attacker can overwrite the encrypted data in the guest system’s memory (at the ciphertext level, without the ability to decrypt) and circumvent the attestation mechanism, for example, to conceal the injection of a backdoor into a virtual machine protected by SEV-SNP technology.

The attack is based on setting up fake parameters in the SPD of the memory module, causing the processor to access non-existent addresses reflected in existing memory areas. The attacker can adjust the SPD so that the memory module reports a size that exceeds the actual characteristics of the module. After this, the attacker can map the fabricated non-existent memory to a real area in the DRAM, which is already being used in an encrypted form in secure guest systems. As a result, a situation arises where different addresses point to the same physical memory (two areas are reflected in one area in the DRAM chip), meaning that the address of the fake reflected memory area can access already used real memory and bypass the memory protection mechanisms in the CPU.

BadRAM attack, which allows bypassing the SEV-SNP attestation mechanism in AMD CPUs

To carry out the attack, it is enough to assemble a simple programmer costing about $10, consisting of a Raspberry Pi Pico microcontroller, a socket for DDR4 / DDR5 modules, and a power supply. The utilities used to perform the attack, the kernel module, and exploit prototypes are hosted on GitHub.

BadRAM attack, which allows bypassing the SEV-SNP attestation mechanism in AMD CPUs

For chips from certain manufacturers that do not have SPD rewrite protection, the attack can be performed programmatically without physical access to the server. For example, the parameters of Corsair memory modules with RGB lighting can be changed programmatically. In the case of a fully software-based attack, the system can be compromised, for instance, through the use of a malicious BIOS update or through sabotage by administrators. servers in cloud services.

BadRAM attack, which allows bypassing the SEV-SNP attestation mechanism in AMD CPUs

As confirmation of the method's effectiveness, two attacks have been demonstrated. The first attack shows the possibility of reproducing the ciphertext — when using AMD SEV, the data in memory is stored in an encrypted form, and the attacker cannot determine the content, but can read the encrypted data and then substitute it for other encrypted content.

The second attack demonstrates the ability to bypass the SEV-SNP attestation mechanism, which provides cryptographic verification of the integrity of a virtual machine running in a secure environment. The attacker can intercept the attestation report of the legitimate virtual machine and then substitute it for the compromised virtual machine, for example, to conceal traces of a backdoor installation.

The issue affects the 3rd and 4th generation AMD EPYC processors, code-named Milan, Milan-X, Genoa, Bergamo, Genoa-X, and Siena. To mitigate the vulnerability, AMD has already released a SEV firmware update that implements ALIAS_CHECK, preventing memory manipulation characteristic of the discussed attack.

Intel's proposed Scalable SGX and TDX technologies are not susceptible to the attack, as they include the necessary checks from the start. The classic Intel SGX technology, which was deprecated by Intel in 2021, is partially vulnerable to the attack (similarly to the previously known MemBuster attack, an attacker can analyze accesses to encrypted memory, meaning only ciphertext reading is possible, but not overwriting). Testing of CCA (Confidential Compute Architecture) extensions in ARM processors has not been conducted.

Additionally, another vulnerability related to AMD SEV-SNP has been reported. The vulnerability was identified in AMD's developing fork of the QEMU emulator intended for running of virtual machines with SEV-SNP. The problem allows the administrator of the host environment to gain root access to guest systems through manipulations with ACPI tables. The vulnerability arises because, during the boot process of the guest system, integrity checks are performed on the Linux kernel, the initial RAM disk, and kernel parameters, but ACPI tables are not taken into account, through which the hypervisor can present specially crafted AML (ACPI Machine Language) code intended for execution in the guest environment. It is claimed that the problem is not specific to QEMU and manifests in any hypervisors and emulators, as the Linux kernel trusts any ACPI data received from the hypervisor.

Play video
Play video


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster