CVE-2020-10255, known as TRRespass, is a RowHammer vulnerability affecting modern DDR4 and LPDDR4 DRAM chips manufactured by SK Hynix, Micron, and Samsung. It exploits weaknesses in the Target Row Refresh (TRR) mitigation, allowing attackers to induce bit flips through specific memory access patterns. This critical vulnerability (CVSS 9.0) can lead to privilege escalation against kernels or Sudo, and cross-tenant VM access by corrupting RSA keys, despite requiring high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:micron:ddr4_sdram:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:micron:lpddr4:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:samsung:ddr4:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:samsung:lpddr4:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:skhynix:ddr4_sdram:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.