Skip to main content

New GPUThor attack defeats NVIDIA ECC protection for root access

0
High
Newsdos
Published: 08/26/2026 (08/26/2026, 18:48:24 UTC)
Source: Bleeping Computer

Description

GPUThor is a newly disclosed Rowhammer attack targeting NVIDIA Ampere-class GPUs with GDDR6 memory, including RTX A4000, A4500, A5000, and A6000. It bypasses NVIDIA's ECC protections by exploiting undocumented GPU behaviors and a non-uniform hammering pattern to induce high bit-flip rates. This enables denial-of-service conditions and root-level privilege escalation by corrupting GPU page tables. The attack was demonstrated to cause GPU resets and eventual hardware marking for replacement. NVIDIA recommends enabling SYS-ECC and IOMMU/DMA isolation, monitoring error telemetry, and restricting untrusted workloads. Complete protection likely requires future hardware-level defenses and stronger multi-bit ECC. No bit flips were observed on tested GDDR6X or HBM2e GPUs using the same attack patterns.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 10:24:19 UTC

Technical Analysis

GPUThor is a Rowhammer attack that circumvents NVIDIA's SECDED ECC memory protections on Ampere-class GPUs with GDDR6 memory by using a non-uniform hammering pattern that avoids triggering Target Row Refresh mitigations. The attack exploits two undocumented GPU behaviors related to memory request coalescing and TRR activation frequency, resulting in bit-flip rates vastly exceeding previous GPU Rowhammer attacks. With ECC enabled, GPUThor still generates detectable double-bit errors and some triple-bit errors that cause incorrect ECC repairs, leading to data corruption. The attack can cause denial-of-service by forcing GPU resets and hardware replacement flags, and can escalate privileges to root by corrupting GPU page tables, granting arbitrary memory access to unprivileged CUDA programs. The attack affects RTX A4000, A4500, A5000, and A6000 GPUs, with potential applicability to server-class Ampere GPUs like the A100. NVIDIA's advisory recommends enabling SYS-ECC and IOMMU/DMA isolation, monitoring GPU error telemetry, and restricting untrusted workloads. The researchers note that future GPUs with stronger multi-bit ECC and hardware defenses will be needed for complete mitigation.

Potential Impact

GPUThor enables denial-of-service by causing periodic GPU resets and eventual hardware marking for replacement on affected NVIDIA GPUs. It also allows privilege escalation to root level by corrupting GPU page tables, enabling unprivileged CUDA programs to gain arbitrary memory access and open a root shell on the host system. This compromises system integrity and confidentiality on systems using vulnerable GPUs. The attack significantly increases bit-flip rates compared to previous GPU Rowhammer attacks, reducing the time to find exploitable bit flips from hours to minutes. While ECC detects many errors, some multi-bit errors cause incorrect ECC repairs leading to data corruption. The risk varies by GPU model and memory technology, with no bit flips observed on tested GDDR6X or HBM2e GPUs.

Defensive Guidance

NVIDIA has published an advisory recommending enabling SYS-ECC and IOMMU/DMA isolation features to mitigate GPUThor. Monitoring GPU error telemetry and restricting the sharing or execution of untrusted CUDA workloads are also advised. Avoiding cross-tenant GPU sharing where possible and monitoring ECC error counters can help detect attacks. Complete protection likely requires future GPUs with stronger multi-bit ECC and hardware-level defenses. Users should consult the official NVIDIA advisory for detailed guidance. Patch status is not explicitly stated; check the vendor advisory for current remediation updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}

Threat ID: 6a8f35e0acd9273b49425c2c

Added to database: 08/26/2026, 18:52:16 UTC

Last enriched: 09/10/2026, 10:24:19 UTC

Last updated: 10/04/2026, 04:51:17 UTC

Views: 90

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses