Security readout for executives and security teams
Plain-English summary
This CVE describes a hardware weakness in modern DDR4 and LPDDR4X memory where built-in Rowhammer protections can be bypassed. In affected systems, carefully varied memory access patterns may cause bit flips, potentially undermining isolation, integrity, or cryptographic material. The sources do not show active exploitation in the wild.
Executive priority
Treat this as a hardware exposure requiring inventory and vendor engagement, not a routine software patch. Prioritize environments with untrusted tenants, sensitive keys, or critical workloads, because remediation may require platform-specific guidance or hardware lifecycle decisions.
Technical view
Blacksmith demonstrated non-uniform Rowhammer patterns that bypass Target Row Refresh on tested PC-DDR4 devices. The CVE reports bit flips across a 40-device test pool covering Samsung, SK Hynix, and Micron, with possible privilege escalation, binary corruption, RSA key impact, and cross-tenant VM risk.
Likely exposure
Exposure is most relevant to systems using DDR4 SDRAM or LPDDR4X memory from Samsung, SK Hynix, or Micron. The strongest evidence covers tested PC-DDR4 devices and DRAM acquired around July 2020; exact exposure requires hardware inventory and vendor confirmation.
Exploitation context
The CVE has high impact but high attack complexity. It is not listed as KEV in the provided bundle, and no cited source confirms active exploitation. Practical risk is higher for shared infrastructure, high-value hosts, and environments relying on memory isolation against untrusted workloads.
Researcher notes
Evidence is strongest for Blacksmith’s tested DDR4 devices and the CVE’s listed DDR4/LPDDR4 vendors. The bundle does not provide a universal patch, confirmed exploit-in-the-wild status, or a complete affected part-number matrix. Avoid extrapolating beyond vendor-confirmed hardware.
Mitigation direction
- Inventory systems using DDR4 SDRAM or LPDDR4X memory.
- Check OEM, platform, and DRAM vendor guidance for affected modules and supported remedies.
- Prioritize shared, multi-tenant, and high-value systems for vendor review.
- Do not assume TRR-marketed memory is immune to Rowhammer.
- Plan hardware replacement if vendors identify no practical remediation.
Validation and detection
- Collect memory vendor, type, part number, and platform details from asset inventory.
- Compare hardware details against vendor advisories and CVE-2021-42114 references.
- Ask cloud or hosting providers about Rowhammer exposure and mitigations.
- Avoid production Rowhammer testing unless explicitly approved and isolated.
- Document systems where vendor exposure status remains unknown.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-20: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-42114 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Critical
- CVSS
- 9 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H2.26Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
9CriticalVector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://comsec.ethz.ch/research/dram/blacksmith/CVE reference · x_refsource_MISC
- https://github.com/comsec-group/blacksmithCVE reference · x_refsource_MISC
- https://comsec.ethz.ch/wp-content/files/blacksmith_sp22.pdfCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
