LiveActive security incident?Get immediate response
CVE Record

CVE-2021-42114: Scalable Rowhammering In the Frequency Domain to Bypass TRR Mitigations On Modern DDR4/LPDDR4X Devices

Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Rowhammer access patterns, consisting of aggressors with different frequencies, phases, and amplitudes allow triggering bit flips on affected memory modules using our Blacksmith fuzzer. The patterns generated by Blacksmith were able to trigger bitflips on all 40 PC-DDR4 DRAM devices in our test pool, which cover the three major DRAM manufacturers: Samsung, SK Hynix, and Micron. This means that, even when chips advertised as Rowhammer-free are used, attackers may still be able to exploit Rowhammer. For example, this enables privilege-escalation attacks against the kernel or binaries such as the sudo binary, and also triggering bit flips in RSA-2048 keys (e.g., SSH keys) to gain cross-tenant virtual-machine access. We can confirm that DRAM devices acquired in July 2020 with DRAM chips from all three major DRAM vendors (Samsung, SK Hynix, Micron) are affected by this vulnerability. For more details, please refer to our publication.

CriticalCVSS 9Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

This CVE describes a hardware weakness in modern DDR4 and LPDDR4X memory where built-in Rowhammer protections can be bypassed. In affected systems, carefully varied memory access patterns may cause bit flips, potentially undermining isolation, integrity, or cryptographic material. The sources do not show active exploitation in the wild.

Executive priority

Treat this as a hardware exposure requiring inventory and vendor engagement, not a routine software patch. Prioritize environments with untrusted tenants, sensitive keys, or critical workloads, because remediation may require platform-specific guidance or hardware lifecycle decisions.

Technical view

Blacksmith demonstrated non-uniform Rowhammer patterns that bypass Target Row Refresh on tested PC-DDR4 devices. The CVE reports bit flips across a 40-device test pool covering Samsung, SK Hynix, and Micron, with possible privilege escalation, binary corruption, RSA key impact, and cross-tenant VM risk.

Likely exposure

Exposure is most relevant to systems using DDR4 SDRAM or LPDDR4X memory from Samsung, SK Hynix, or Micron. The strongest evidence covers tested PC-DDR4 devices and DRAM acquired around July 2020; exact exposure requires hardware inventory and vendor confirmation.

Exploitation context

The CVE has high impact but high attack complexity. It is not listed as KEV in the provided bundle, and no cited source confirms active exploitation. Practical risk is higher for shared infrastructure, high-value hosts, and environments relying on memory isolation against untrusted workloads.

Researcher notes

Evidence is strongest for Blacksmith’s tested DDR4 devices and the CVE’s listed DDR4/LPDDR4 vendors. The bundle does not provide a universal patch, confirmed exploit-in-the-wild status, or a complete affected part-number matrix. Avoid extrapolating beyond vendor-confirmed hardware.

Mitigation direction

  • Inventory systems using DDR4 SDRAM or LPDDR4X memory.
  • Check OEM, platform, and DRAM vendor guidance for affected modules and supported remedies.
  • Prioritize shared, multi-tenant, and high-value systems for vendor review.
  • Do not assume TRR-marketed memory is immune to Rowhammer.
  • Plan hardware replacement if vendors identify no practical remediation.

Validation and detection

  • Collect memory vendor, type, part number, and platform details from asset inventory.
  • Compare hardware details against vendor advisories and CVE-2021-42114 references.
  • Ask cloud or hosting providers about Rowhammer exposure and mitigations.
  • Avoid production Rowhammer testing unless explicitly approved and isolated.
  • Document systems where vendor exposure status remains unknown.
Prepared
Confidence
high
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-20: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-42114 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9CVSS 3.1CriticalCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H2.26Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

9Critical
CVSS 3.1 vector shape for CVE-2021-42114Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
MicronMicron ddr4_sdram1Listed
SamsungSamsung ddr4_sdram1Listed
SK HynixSK Hynix ddr4_sdram1Listed
MicronMicron lpddr41Listed
SamsungSamsung lpddr41Listed
SK HynixSK Hynix lpddr41Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.