CVE-2025-6202, dubbed Phoenix, is a Rowhammer vulnerability affecting SK Hynix DDR5 DIMMs produced from 2021-01 through 2024-12 on x86 systems. According to the provided content, researchers reverse engineered the DIMMs' in-DRAM Target Row Refresh (TRR) behavior and developed long hammering patterns (including 128 tREFI and 2608 tREFI patterns) plus a self-correcting refresh-synchronization technique that bypasses DDR5 TRR protections and induces exploitable bit flips. The issue affects hardware integrity by allowing a local attacker to manipulate DRAM contents despite DDR5 mitigations and on-die ECC. The content states the attack was demonstrated across all 15 tested vulnerable SK Hynix DDR5 UDIMMs and can be used to corrupt sensitive memory structures such as page table entries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RowHammer variant (Phoenix) against DDR5 memory that bypasses advanced mitigations.
The content references CVE-2025-6202 as a critical SK Hynix DDR5 vulnerability associated with Rowhammer-style private key compromise, but provides no further technical detail in the analyzed text.
A CVE mentioned only in a previous-post reference, described as tied to an SK Hynix DDR5 vulnerability, with no substantive discussion in the main content.
A Rowhammer vulnerability affecting SK Hynix DDR5 memory that bypasses modern TRR protections and enables induced bit flips, supporting scenarios such as privilege escalation, key extraction from co-located VMs, and manipulation of cryptographic material in memory.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.