Pith. sign in

REVIEW 1 cited by

Rowhammer.js: A Remote Software-Induced Fault Attack in JavaScript

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1507.06955 v5 pith:64YLYYT2 submitted 2015-07-24 cs.CR

classification cs.CR
keywords memoryrowhammerattackcachesystemstriggeraccessesaccessing
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

A fundamental assumption in software security is that a memory location can only be modified by processes that may write to this memory location. However, a recent study has shown that parasitic effects in DRAM can change the content of a memory cell without accessing it, but by accessing other memory locations in a high frequency. This so-called Rowhammer bug occurs in most of today's memory modules and has fatal consequences for the security of all affected systems, e.g., privilege escalation attacks. All studies and attacks related to Rowhammer so far rely on the availability of a cache flush instruction in order to cause accesses to DRAM modules at a sufficiently high frequency. We overcome this limitation by defeating complex cache replacement policies. We show that caches can be forced into fast cache eviction to trigger the Rowhammer bug with only regular memory accesses. This allows to trigger the Rowhammer bug in highly restricted and even scripting environments. We demonstrate a fully automated attack that requires nothing but a website with JavaScript to trigger faults on remote hardware. Thereby we can gain unrestricted access to systems of website visitors. We show that the attack works on off-the-shelf systems. Existing countermeasures fail to protect against this new Rowhammer attack.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. DejaVu: Why You Should Write to Your DRAM Rows Twice, Carefully

    cs.AR 2026-06 unverdicted novelty 7.0 of 10

    DejaVu is a newly characterized data-pattern effect in commercial DDR4 DRAM where double-writing rows alters read-disturbance bitflip thresholds, shown across 112 chips and with implications for PUD operations.

Pith tools