Matej Bölcskei

dblp:381/1639 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Rubicon: Precise Microarchitectural Attacks with Page-Granular Massaging
abstract
Microarchitectural attacks like Rowhammer and Spectre rely on precisely targeting specific memory page frames despite the inherent unpredictability of memory allocation. Due to the lack of a generic mechanism to accurately place the target data in the pages of interest, these attacks resort to spraying their target or scanning the entire physical memory for it. These approaches, however, suffer from unreliability and inefficiency. In contrast, the deterministic behavior of page allocators presents an opportunity to enhance existing attacks and enable new ones.This paper introduces Rubicon, a novel technique for page-granular physical memory massaging within the Linux kernel’s Zoned Buddy Allocator (ZBA). Rubicon leverages three new primitives that enable placing a page frame at the head of any chosen ZBA free list, ensuring it is prioritized for allocation regardless of its initial state or per-CPU freelist association. Using Rubicon, we build the first deterministic privilege escalation Rowhammer exploit on x86 with a success rate of 100%. Our integration of Rubicon into a recent Spectre attack shows that the root hash of /etc/shadow can now be leaked in 27.8 and 9.5 seconds on AMD and Intel systems — a 6.8× and 284× speedup over the original attack, respectively. We also propose and evaluate practical mitigations for Rubicon, which limit page movement between ZBA lists with negligible performance and fragmentation impact.
Matej Bölcskei, Patrick Jattke, Johannes Wikner, Kaveh Razavi
EuroS&P1
2025 Encarsia: Evaluating CPU Fuzzers via Automatic Bug Injection
Matej Bölcskei, Flavien Solt, Katharina Ceesay-Seitz, Kaveh Razavi
USENIX Security Symposium1
2024 ZenHammer: Rowhammer Attacks on AMD Zen-based Platforms
Patrick Jattke, Max Wipfli, Flavien Solt, Michele Marazzi, Matej Bölcskei, Kaveh Razavi
USENIX Security Symposium5