{"id":2560,"date":"2026-08-27T09:30:12","date_gmt":"2026-08-27T09:30:12","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2560"},"modified":"2026-08-27T09:30:12","modified_gmt":"2026-08-27T09:30:12","slug":"new-gputhor-rowhammer-defeats-ecc-on-nvidia-rtx-a6000-to-gain-host-root-access","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2560","title":{"rendered":"New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj2AxQ4SD6_1WKkpvBVi_M7oKLMeBAiKU4Ek4HbnJXHLX5xSbUg7ky1ITdUJY91n-zZGyK55-qQRd24PWRymLmik7cRl4CYPoaeZL5JuLedlsOTJGHChwF1eQWGhUE6AhOZUSW7CoajwQcKCu8E_zrYn8I6203Nrvr9NvheYL-5ISm0fs1xdWNiKGWqIs0\/s1700-e365\/nvidia-bits.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.<\/p>\n<p>Dubbed <strong>GPUThor<\/strong>, the attack was developed by researchers at the University of Toronto, who hammered four DRAM banks for 24 hours each on four Ampere-class cards, inducing bit flips on each.<\/p>\n<p>The following GPUs were tested and found vulnerable &#8211;<\/p>\n<ul>\n<li>RTX A6000 (48 GB GDDR6)<\/li>\n<li>RTX A5000 (24 GB GDDR6)<\/li>\n<li>RTX A4500 (20 GB GDDR6)<\/li>\n<li>RTX A4000 (16 GB GDDR6)<\/li>\n<\/ul>\n<p>Mounting the attack requires the ability to launch an unprivileged CUDA kernel on the target GPU, either as a co-tenant on a shared card or as untrusted code on a single-tenant machine. The researchers advise avoiding cross-tenant GPU sharing, monitoring ECC error counters, and restricting untrusted CUDA workloads.<\/p>\n<p>\u00abRecently, researchers at the University of Toronto demonstrated a successful Rowhammer exploitation on an NVIDIA A6000 GPU with GDDR6 memory where System-Level ECC was not enabled. In the same paper, the researchers showed that enabling System-Level ECC mitigates the Rowhammer problem,\u00bb NVIDIA said in <a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5671\" target=\"_blank\">a July 2025 security notice<\/a>.<\/p>\n<p>That notice followed GPUHammer, the same team&#8217;s earlier work, and the first GPU Rowhammer attack demonstrated on NVIDIA hardware, which yielded 16-bit flips per gigabyte on an RTX A6000 and was neutralized once ECC was enabled.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>What GPUThor adds is non-uniform hammering, where the aggressor row next to the victim is activated far more often than the decoy rows used to swamp the memory&#8217;s Target Row Refresh (TRR) defense. Prior GPU attacks activated aggressor and decoy rows at roughly the same rate.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The researchers found that repeated accesses issued inside a single warp, the group of 32 threads a GPU runs in lockstep, are merged at the memory controller into a single DRAM activation.<\/p>\n<p>Accesses issued from different warps to different cache lines within the same row survive as separate activations, and the hammering kernels distribute them accordingly.<\/p>\n<p>They also reported in the <a href=\"https:\/\/gururaj-s.github.io\/assets\/pdf\/CCS26_GPUThor.pdf\" target=\"_blank\">GPUThor paper<\/a> that TRR on these GDDR6 parts likely applies about once every 72 refresh intervals rather than once per interval, and built a six-interval pattern around that schedule.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQswFpRMIX5gG_g40EtMGn3N_sK_jVIfsbWAmoitGC2pvlg7xvocS-3gX6UKhU9qUFyGY1qT_3wZMOMaPdf34nz3h_WUNGfh1AVcwsoqE9r3d9TJnIh4jC3dacb08tQT392HDkPzJbEV2wMCcpxL-0ln3uTUahvpWaIPcGfAJ14E30XKRl_ombY8tnzmQ\/s1700-e365\/bits.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQswFpRMIX5gG_g40EtMGn3N_sK_jVIfsbWAmoitGC2pvlg7xvocS-3gX6UKhU9qUFyGY1qT_3wZMOMaPdf34nz3h_WUNGfh1AVcwsoqE9r3d9TJnIh4jC3dacb08tQT392HDkPzJbEV2wMCcpxL-0ln3uTUahvpWaIPcGfAJ14E30XKRl_ombY8tnzmQ\/s1700-e365\/bits.jpg\" alt=\"\" border=\"0\" data-original-height=\"542\" data-original-width=\"1007\"\/><\/a><\/div>\n<p>Across the four cards, the campaigns produced 72,000 to 377,000 bit flips per gigabyte with ECC disabled.<\/p>\n<p>The RTX A5000 was the most susceptible at 377,552 flips per gigabyte, which is 23,597 times GPUHammer&#8217;s 16 flips per gigabyte and roughly 500 times the 758 flips per gigabyte reported for GDDRHammer, the strongest prior GPU Rowhammer attack.<\/p>\n<p>The paper places the A5000 rate close to the roughly 550,000 flips per gigabyte reached by Blacksmith, which established non-uniform hammering on DDR4 as a route past in-DRAM defenses.<\/p>\n<p>At a 16-byte granularity, the campaigns turned up 387 double-bit flips and two triple-bit flips across the four cards with ECC disabled, with the A5000 accounting for 306 of the double-bit flips and both triple-bit flips.<\/p>\n<p>The single-error-correct, double-error-detect (SECDED) ECC on these GPUs corrects one flipped bit in a protected chunk and detects two, and the researchers found that it mis-corrects three, resulting in silent data corruption (SDC).<\/p>\n<p>With ECC enabled on a locally owned RTX A6000, one bank of hammering produced 11 detectable, uncorrectable errors (DUE) and one SDC over a day, an average of one DUE every two hours. Each DUE aborts all kernels running on the card, leaving it unusable until a reset.<\/p>\n<p>For the escalation itself, the researchers reused the exploit code from GPUBreach, their earlier GPU page-table privilege escalation research.<\/p>\n<p>Page tables are first massaged into a vulnerable row. The neighboring rows are then hammered to corrupt the page-frame number of an entry. A second kernel reaches memory outside the process through the tampered entry.<\/p>\n<p>Using the triple-bit SDC, the researchers obtained root on the host with the IOMMU enabled. Using a double-bit DUE, they achieved host-side privilege escalation on systems where the IOMMU is disabled. A page-table entry is repointed at CPU memory. The process credential structure is then overwritten.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh3LbYA7qJ9a4i5qFKNOA7R-E69EMwKknI28ULQHAPhNS-ZiWw5BRigu3Aj17MU-WCDMgWFMsBmEo88qzLHGKg7pVTnLmR4rt4pQ4lpZG-ovFBc0kQp45bsGK3nLKimNT4phida3FO1F-Cc7fV1tWdEKa1fxMTV56p269VVO8IuwtNB80YP0YlYG15jxmU\/s1700-e365\/flips.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh3LbYA7qJ9a4i5qFKNOA7R-E69EMwKknI28ULQHAPhNS-ZiWw5BRigu3Aj17MU-WCDMgWFMsBmEo88qzLHGKg7pVTnLmR4rt4pQ4lpZG-ovFBc0kQp45bsGK3nLKimNT4phida3FO1F-Cc7fV1tWdEKa1fxMTV56p269VVO8IuwtNB80YP0YlYG15jxmU\/s1700-e365\/flips.jpg\" alt=\"\" border=\"0\" data-original-height=\"401\" data-original-width=\"1040\"\/><\/a><\/div>\n<p>\u00abMoreover, we discover that even double-bit DUEs are exploitable, since DUEs are serviced lazily in NVIDIA GPUs, leaving a ~10 ms time window between DUE detection and the GPU being killed, during which the corrupted data is consumed by the attacker&#8217;s GPU kernel,\u00bb the researchers said.<\/p>\n<p>Locating exploitable multi-bit errors without setting off a DUE took about four days on the A6000. An end-to-end privilege escalation that took 21.9 hours on that card was completed in 1.1 minutes with GPUHammer&#8217;s patterns and in 1.1 minutes with GPUThor&#8217;s.<\/p>\n<p>The same patterns produced no bit flips on the other NVIDIA parts tested, including an A10, an L4, and an L40 on GDDR6, an RTX 4090 on GDDR6X, and an A30 on HBM2e.<\/p>\n<p>\u00abWe also tested other memory types (see Appendix D), including HBM, GDDR6X, and newer-generation GDDR6 on NVIDIA GPUs, and did not observe any bit flips on them. This is likely due to differing TRR implementations in these memories compared to the A4000-A6000 GPUs, which make GPUThor&#8217;s patterns unsuccessful,\u00bb the researchers said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The A100 and H100 were outside the tested set.<\/p>\n<p>Server-class Ampere GPUs and newer carry Error Containment and Dynamic Page Offlining, which confine a fault to the triggering application, but they still rely on SECDED-level ECC, and the researchers said an SDC-based escalation could still work against them. RAS Repair on some Blackwell GPUs makes the DUE-based route more time-consuming without preventing it, they said.<\/p>\n<p>GPUThor was reported to NVIDIA on April 29, 2026, and to Google, Microsoft, and AWS. The findings were then subject to an embargo that ran until August 25, 2026. NVIDIA released <a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5873\" target=\"_blank\">a security notice<\/a> with guidance at the end, the researchers said.<\/p>\n<p>GPUThor does not carry a CVE identifier, and no in-the-wild exploitation has been reported as of August 27, 2026. No patch addresses the attack, and the researchers said a complete fix would require stronger multi-bit error correction and in-DRAM defenses, such as Refresh Management or Per-Row Activation Counting, in future GPUs.<\/p>\n<p>The attack code is due for public release on November 15, 2026, the opening day of the ACM Conference on Computer and Communications Security, where the paper will be presented.<\/p>\n<p>The Hacker News contacted NVIDIA for comment on whether ECC remains a sufficient mitigation and the University of Toronto researchers for further detail; neither had responded by publication.<\/p>\n<p>\u00abWe used these to crash GPUs and to escalate privileges with ECC enabled. ECC still raises the bar and remains worth enabling, but it can no longer be treated as a sufficient defense,\u00bb the researchers said on the <a href=\"https:\/\/gputhor.com\/\" target=\"_blank\">GPUThor project site<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2561,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3194,130,3191,3192,580,3189,1109,2532,61,3190,3193],"class_list":["post-2560","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-a6000","tag-access","tag-defeats","tag-ecc","tag-gain","tag-gputhor","tag-host","tag-nvidia","tag-root","tag-rowhammer","tag-rtx"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2560"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2560\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2561"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}