AES being linear or not is wholly irrelevant for this.
I recommend you read this article: https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation
I recommend you read this article: https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation
Same way Rowhammer works. Exploiting a physical vulnerability gives zero damns about encryption. Now whether you get VALID or USABLE data from the attack is an entirely different story.