Spaghettifying DRAM: Unlock Everything on the CPU

A new exploit targets the DRAM controller's address translation to scramble physical memory, bypassing all higher-level protections. By flipping a single bit in the memory controller, researchers can access hidden regions like the Platform Security Processor, System Management Mode, and CPU microcode. The technique, demonstrated on AMD Family 16h CPUs, uses linear algebra to reconstruct the scrambled memory and works even on modern architectures.
Physical addresses are really more of a suggestion.