Christopher Domas published tooling that flips one configuration bit in an AMD DRAM controller to rewire how physical addresses map onto memory chips, letting ring 0 code read the PSP carveout, SMM handlers, C6 core state and microcode patch RAM without ever defeating the protections that guard them.

Read the full story: Spaghettifying DRAM: attack reads AMD's PSP and SMM memory →

Transcript

Every memory protection on your machine works the same way. It looks at a physical address and decides yes or no. Christopher Domas just published tooling that never asks. He flips one bit in an AMD memory controller. Bit twenty two, one register. And the whole map of how addresses land on real memory chips gets rewired underneath. The address you were allowed to touch now lands on the capacitors holding the things you were not. The firmware TPM's crypto routines. System management mode handlers, running below the kernel. Even the CPU's own microcode, backed up in memory so it survives idle. Nothing was bypassed. The guards said yes, correctly, every single time. Tested on AMD's twenty thirteen era chips, because those are the last ones AMD documented.