[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8OuUqodsAFIk5lJdspc8X3Ok5mRA4KttUlX5eUfd7QU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"dac403c9-1107-413f-a10d-d9183215eaca","gputhor-rowhammer-attack-bypasses-ecc-to-escalate-privileges-on-nvidia-rtx-gpus","9913fae5-c380-4151-aa23-1873b4c9dd4b","GPUThor Rowhammer Attack Bypasses ECC to Escalate Privileges on NVIDIA RTX GPUs","The GPUThor attack exposes a fundamental hardware-level vulnerability in NVIDIA GDDR6-based workstation GPUs, demonstrating that Error Correction Codes (ECC) — long considered a reliable Rowhammer mitigation — can be defeated by a sufficiently crafted attack pattern. An unprivileged user with the ability to launch a CUDA kernel can exploit memory bit-flip manipulation to achieve full root access on the host system, completely bypassing software-level access controls. This is particularly concerning in multi-tenant environments, cloud GPU workloads, and AI\u002FML research clusters where shared GPU access is common. The attack highlights that hardware mitigations should not be treated as absolute security guarantees, and that defense-in-depth strategies must account for their potential failure. Organizations relying solely on ECC as a Rowhammer defense need to urgently reassess their GPU security posture.","**Immediate actions:**\n- Restrict or audit who has permission to launch CUDA kernels on exposed GPU workstations, especially in shared or multi-tenant environments.\n- Apply any vendor-issued firmware or driver patches from NVIDIA addressing Rowhammer-class vulnerabilities as soon as they become available.\n- Isolate affected GPU models (RTX A6000, A5000, A4500, A4000) from sensitive workloads or root-privileged processes until mitigations are validated.\n\n**Long-term improvements:**\n- Enforce least-privilege principles so that unprivileged users cannot access GPU compute resources without explicit, audited authorization.\n- Treat hardware-level mitigations like ECC as one layer in a defense-in-depth strategy rather than a standalone control, combining them with OS-level sandboxing and workload isolation.\n- Maintain a complete and current hardware inventory tagging GPU models and memory types to rapidly scope exposure when new hardware vulnerabilities are disclosed.\n\n**Detection measures:**\n- Deploy monitoring for anomalous GPU memory access patterns or unexpected CUDA kernel executions that could indicate active Rowhammer exploitation attempts.\n- Establish alerting on unexpected privilege escalation events or root shell activity originating from GPU compute processes.\n- Regularly review and audit GPU workload logs in AI\u002FML and research environments to detect unauthorized lateral movement or privilege changes.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4: Controlled Use of Administrative Privileges","CIS Control 7: Continuous Vulnerability Management","CIS Control 18: Penetration Testing","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 AU-12: Audit Record Generation","NIST CSF ID.AM-1: Physical device inventory","NIST CSF PR.AC-4: Access permissions and authorizations managed","ISO\u002FIEC 27001 A.12.6.1: Management of Technical Vulnerabilities","ISO\u002FIEC 27001 A.9.4.1: Information Access Restriction","published","2026-08-27T10:21:32.385394+00:00","2026-08-27T10:21:32.276+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fgputhor-rowhammer-defeats-ecc-on-nvidia.html","new-gputhor-rowhammer-defeats-ecc-on-nvidia-rtx-a6000-to-gain-host-root-access-1cf6d1","New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]