← All articles

GPUThor Rowhammer defeats ECC on NVIDIA GPUs to reach host root

Academic researchers disclosed GPUThor, a Rowhammer attack that defeats the error-correcting memory that NVIDIA recommends as the defense against GPU Rowhammer. Demonstrated on Ampere-class workstation GPUs with GDDR6 memory, including the RTX A4000 through A6000 models common in AI and cloud infrastructure, it lets unprivileged code running on the GPU flip memory bits far more reliably than earlier attacks, finding an exploitable flip in about a minute. That enables denial of service, silent data corruption, and escalation to a root shell on the host. The researchers note error correction is not sufficient protection, which matters most where untrusted workloads share GPUs, as in multi-tenant cloud and AI platforms.

Check
Where GPUs run untrusted or multi-tenant workloads, avoid sharing a physical GPU across tenants, limit who can run arbitrary GPU code, and monitor for unusual error-correction events on affected NVIDIA cards.
Affected
Systems running untrusted GPU workloads on affected NVIDIA Ampere workstation cards with GDDR6 memory; unprivileged GPU code can flip memory bits despite error correction, causing denial of service or host root access.
Fix
Isolate GPU workloads and avoid cross-tenant sharing of physical GPUs, restrict arbitrary code execution on shared GPUs, monitor error-correction telemetry for hammering, and follow vendor guidance as hardware-level mitigations develop.