GPUThor: an evolution of the Rowhammer idea
GPUThor is a new Rowhammer attack technique targeting Nvidia Ampere GPUs with GDDR6 memory, significantly increasing the effectiveness of bit flips in video memory. It exploits a hardware behavior where repeated memory access can corrupt data in neighboring cells, bypassing standard defenses like Target Row Refresh (TRR). The attack can cause double and triple-bit errors, which are not fully corrected by ECC memory, leading to denial of service conditions such as GPU reboots and hardware faults. While arbitrary code execution has not been demonstrated, the attack shows a theoretical potential to compromise industrial GPUs and cloud infrastructure using such accelerators.
AI Analysis
Technical Summary
GPUThor is an advanced Rowhammer attack developed by University of Toronto researchers that targets Nvidia Ampere GPUs (models A4000, A4500, A5000, A6000) equipped with GDDR6 memory. It improves on previous GPU Rowhammer attacks by exploiting the TRR mechanism's refresh cycle limitation, triggering bit flips at a rate 7,000 to 23,000 times higher than prior methods. This results in 72,000 to 377,000 bit flips per gigabyte, enabling double and triple-bit errors that ECC memory cannot fully correct. The attack can cause denial of service by forcing GPU reboots and hardware faults, although arbitrary code execution remains unproven. The research highlights the ongoing risk of Rowhammer attacks on GPU memory, especially in cloud environments where GPUs are shared resources.
Potential Impact
The attack can cause significant data corruption in GPU video memory, resulting in denial of service conditions such as GPU reboots and hardware faults that require replacement. ECC memory protection is insufficient against double and triple-bit errors induced by GPUThor. Although arbitrary code execution has not been demonstrated, the increased effectiveness of the attack suggests a theoretical risk to cloud infrastructure and industrial GPU deployments. No confirmed exploits in the wild are reported, and the attack remains largely theoretical and experimental at this stage.
Mitigation Recommendations
No official patch or fix is currently available for GPUThor. Standard ECC memory protection is insufficient against the double and triple-bit errors caused by this attack. Cloud providers and GPU users should monitor vendor advisories for updates. Given the attack's theoretical nature and lack of demonstrated arbitrary code execution, immediate urgent remediation is not required, but awareness and cautious use of shared GPU resources are advised. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
GPUThor: an evolution of the Rowhammer idea
Description
GPUThor is a new Rowhammer attack technique targeting Nvidia Ampere GPUs with GDDR6 memory, significantly increasing the effectiveness of bit flips in video memory. It exploits a hardware behavior where repeated memory access can corrupt data in neighboring cells, bypassing standard defenses like Target Row Refresh (TRR). The attack can cause double and triple-bit errors, which are not fully corrected by ECC memory, leading to denial of service conditions such as GPU reboots and hardware faults. While arbitrary code execution has not been demonstrated, the attack shows a theoretical potential to compromise industrial GPUs and cloud infrastructure using such accelerators.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GPUThor is an advanced Rowhammer attack developed by University of Toronto researchers that targets Nvidia Ampere GPUs (models A4000, A4500, A5000, A6000) equipped with GDDR6 memory. It improves on previous GPU Rowhammer attacks by exploiting the TRR mechanism's refresh cycle limitation, triggering bit flips at a rate 7,000 to 23,000 times higher than prior methods. This results in 72,000 to 377,000 bit flips per gigabyte, enabling double and triple-bit errors that ECC memory cannot fully correct. The attack can cause denial of service by forcing GPU reboots and hardware faults, although arbitrary code execution remains unproven. The research highlights the ongoing risk of Rowhammer attacks on GPU memory, especially in cloud environments where GPUs are shared resources.
Potential Impact
The attack can cause significant data corruption in GPU video memory, resulting in denial of service conditions such as GPU reboots and hardware faults that require replacement. ECC memory protection is insufficient against double and triple-bit errors induced by GPUThor. Although arbitrary code execution has not been demonstrated, the increased effectiveness of the attack suggests a theoretical risk to cloud infrastructure and industrial GPU deployments. No confirmed exploits in the wild are reported, and the attack remains largely theoretical and experimental at this stage.
Mitigation Recommendations
No official patch or fix is currently available for GPUThor. Standard ECC memory protection is insufficient against the double and triple-bit errors caused by this attack. Cloud providers and GPU users should monitor vendor advisories for updates. Given the attack's theoretical nature and lack of demonstrated arbitrary code execution, immediate urgent remediation is not required, but awareness and cautious use of shared GPU resources are advised. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Classification
- {"confidence":0.76,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.kaspersky.com/blog/gputhor-rowhammer-class-attack/56362/","fetched":true,"fetchedAt":"2026-09-08T16:05:32.578Z","wordCount":1250}
Threat ID: 6aa0324cacd9273b49e300df
Added to database: 09/08/2026, 16:05:32 UTC
Last enriched: 09/08/2026, 16:05:41 UTC
Last updated: 09/08/2026, 19:29:22 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.