University of Toronto researchers disclosed GPUThor, a GPU-based Rowhammer technique that can bypass practical protections provided by SECDED ECC on certain NVIDIA Ampere workstation GPUs using GDDR6 memory, including the RTX A6000. By using a non-uniform memory-hammering pattern that accounts for undocumented request coalescing and Target Row Refresh behavior, the technique substantially increases bit-flip rates and can trigger uncorrectable double-bit errors or incorrect repair of triple-bit errors.
An attacker needs to execute an unprivileged CUDA kernel, creating risk in shared GPU-tenancy environments and from untrusted local GPU workloads. The researchers demonstrated data corruption and GPU denial of service and described a path to host root privilege escalation through GPU page-table corruption. NVIDIA recommends enabling System-Level ECC (SYS-ECC), enforcing IOMMU/DMA isolation, monitoring GPU ECC telemetry, and restricting untrusted or cross-tenant GPU workloads; no CVE, patch, or confirmed in-the-wild exploitation was reported.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The GPUThor vulnerability disclosure embargo ended. The researchers stated that no patch or CVE had been issued for the technique.
NVIDIA published an advisory with mitigations for GPUThor, including enabling system-level ECC and IOMMU/DMA isolation, monitoring GPU error telemetry, and restricting untrusted or shared GPU workloads.
University of Toronto researchers reported the GPUThor Rowhammer technique to NVIDIA and notified Google, Microsoft, and AWS. The issue affects certain Ampere-class NVIDIA GPUs with GDDR6 memory and can induce multi-bit errors despite SECDED ECC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcenvidia.custhelp.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.