Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

GPUThor attack challenges Nvidia’s ECC defense for workstation GPUs

Four researchers at the University of Toronto have disclosed GPUThor, a Rowhammer technique that can bypass the error-correction protection Nvidia has recommended for its GPUs. They are expected to present the work at ACM CCS 2026.

The attack targets Ampere-generation workstation cards with GDDR6 memory, including the RTX A4000, RTX A4500, RTX A5000 and RTX A6000. An unprivileged CUDA program can use the technique to obtain a root shell on the host without directly accessing a victim’s data, creating a possible path to tampering, sandbox escape and privilege escalation.

GPUThor uses non-uniform hammering to work around the in-chip TRR countermeasure. With ECC disabled, it produced 72,000 to 377,000 bit flips per gigabyte across four Ampere-based cards. The Nvidia A5000 was reported as the most vulnerable, approaching the roughly 550,000 flips per gigabyte achieved by Blacksmith on DDR4.

The researchers said ECC reduced but did not eliminate the problem, producing double-bit errors and 2 triple-bit errors that were corrected to the wrong value. On an RTX A6000 with ECC enabled, GPUThor forced one GPU reset every 2 hours; the card then marked itself RMA-read within a day.

The team disclosed the attack to Nvidia on 29 April 2026, then to Google, Microsoft and AWS, and held the work until 25 August. A code release is scheduled for 15 November. No CVE information or patch is currently available.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.