Nvidia GPU GPUBreach Rowhammer-style page-table corruption privilege-escalation flaw
Vulnerability
Summary
Hide ▲
Show ▼
Researchers demonstrated GPUBreach, a Rowhammer-style weakness in Nvidia GPUs that can corrupt GPU page tables and enable arbitrary read-write access. When paired with Nvidia driver memory-safety bugs, the flaw can escalate to root shell privileges and full system compromise. The risk is highest in shared-GPU cloud environments, and the team reported the issue to Nvidia in November 2025.
Related Happenings
Windows cldflt.sys MiniPlasma privilege escalation zero-day privilege-escalation flaw
Vulnerability
First: 18.05.2026 07:59
Last: 18.05.2026 07:59
Sources 1
About this happening:
**MiniPlasma** is a **Windows privilege-escalation zero-day** in **cldflt.sys** that can give attackers **SYSTEM** privileges on **fully patched Windows systems**. The flaw affect...
Windows cldflt.sys MiniPlasma privilege escalation zero-day privilege-escalation flaw
VulnerabilityAbout this happening: **MiniPlasma** is a **Windows privilege-escalation zero-day** in **cldflt.sys** that can give attackers **SYSTEM** privileges on **fully patched Windows systems**. The flaw affect...
Windows cldflt.sys privilege escalation (CVE-2020-17103)
Vulnerability
First: 18.05.2026 01:30
Last: 18.05.2026 01:30
Sources 1
About this happening:
A public **MiniPlasma** proof-of-concept has renewed concern around the **Windows cldflt.sys Cloud Filter driver** because it can elevate a **standard user** to **SYSTEM** on **fu...
Windows cldflt.sys privilege escalation (CVE-2020-17103)
VulnerabilityAbout this happening: A public **MiniPlasma** proof-of-concept has renewed concern around the **Windows cldflt.sys Cloud Filter driver** because it can elevate a **standard user** to **SYSTEM** on **fu...
Pwn2Own Berlin 2026 multi-product zero-days privilege-escalation flaw
Vulnerability
First: 14.05.2026 21:53
Last: 14.05.2026 21:53
Sources 1
About this happening:
**Pwn2Own Berlin 2026** opened with **24 unique zero-days** demonstrated against **fully patched products**, creating immediate exposure across browser, OS, virtualization, enterp...
Pwn2Own Berlin 2026 multi-product zero-days privilege-escalation flaw
VulnerabilityAbout this happening: **Pwn2Own Berlin 2026** opened with **24 unique zero-days** demonstrated against **fully patched products**, creating immediate exposure across browser, OS, virtualization, enterp...
Linux kernel Dirty Frag and Copy Fail 2 privilege escalation (multiple vulnerabilities)
Vulnerability
First: 11.05.2026 11:15
Last: 11.05.2026 11:15
Sources 1
About this happening:
A newly disclosed **Linux kernel** local privilege-escalation flaw, **Dirty Frag and Copy Fail 2**, can let an unprivileged user reach **root** on affected systems. The bug chains...
Linux kernel Dirty Frag and Copy Fail 2 privilege escalation (multiple vulnerabilities)
VulnerabilityAbout this happening: A newly disclosed **Linux kernel** local privilege-escalation flaw, **Dirty Frag and Copy Fail 2**, can let an unprivileged user reach **root** on affected systems. The bug chains...
GFN.am Armenian GeForce NOW user data leak
Data Leak
First: 08.05.2026 19:18
Last: 08.05.2026 19:18
Sources 1
About this happening:
A **data breach** exposed **GFN.am** GeForce NOW user records in **Armenia**, creating privacy and account-risk exposure. The exposed data included **full names**, **email address...
GFN.am Armenian GeForce NOW user data leak
Data LeakAbout this happening: A **data breach** exposed **GFN.am** GeForce NOW user records in **Armenia**, creating privacy and account-risk exposure. The exposed data included **full names**, **email address...
Timeline
-
07.04.2026 14:31 2 articles · 1mo ago
Researchers disclose GPUBreach GPU Rowhammer flaw
Initial DisclosureUniversity of Toronto researchers disclosed GPUBreach, a GPU Rowhammer attack that can induce GDDR6 bit flips to corrupt GPU page tables, enable arbitrary read-write access, and, together with Nvidia driver memory-safety bugs, escalate to root shell privileges and full system compromise; the findings were reported to Nvidia in November 2025, and Microsoft, AWS, and Google were notified because of potential cloud impact.
Show sources
- GPUBreach: Root Shell Access Achieved via GPU Rowhammer Attack — www.securityweek.com — 07.04.2026 14:31
- GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise — www.infosecurity-magazine.com — 07.04.2026 18:05