Find notable cyber news and cases, enriched with sources, timelines, and signals.

NVIDIA Ampere-class GPUs GPUThor Rowhammer ECC bypass privilege-escalation flaw

Vulnerability
First reported
Last updated
Happening score
H score 26
2 unique sources, 2 articles

Summary

Hide ▲

GPUThor is a Rowhammer vulnerability affecting NVIDIA workstation GPUs with GDDR6 memory that can defeat ECC and enable denial-of-service plus host root privilege escalation. University of Toronto researchers said they tested RTX A6000, RTX A5000, RTX A4500, and RTX A4000 cards, used non-uniform hammering to bypass Target Row Refresh (TRR), and reported April 29, 2026 notification to NVIDIA. NVIDIA later issued guidance recommending SYS-ECC, IOMMU/DMA isolation, GPU error telemetry monitoring, and restricting untrusted CUDA workloads. The researchers said there is no CVE and no patch for the attack.

Related Happenings

NVIDIA GPUThor mitigation advisory

Advisory/Mitigation
H score29 First: 26.08.2026 21:48 Last: 26.08.2026 21:48 Sources 1

How related: The researchers reported their findings to NVIDIA on April 29, and on August 21, the company published an advisory providing guidance.

About this happening: University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA workstation GPUs with GDDR6 memory that can bypass ECC, trigger denial...

Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)

Vulnerability
H score10 First: 11.08.2026 15:05 Last: 11.08.2026 15:05 Sources 1

About this happening: CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code...

Bit2Watt GPU power modulation research on grid destabilization

Technical Analysis
H score22 First: 21.07.2026 14:24 Last: 21.07.2026 14:24 Sources 1

About this happening: Researchers published Bit2Watt, showing that ordinary cloud GPU workloads can be shaped into kilohertz-range power oscillations that may destabilize grid behavior...

CERT/CC UEFI DBX mitigation for vendor-signed applications

Advisory/Mitigation
H score28 First: 19.06.2026 21:33 Last: 19.06.2026 21:33 Sources 1

About this happening: CERT/CC issued mitigation guidance to apply UEFI Forbidden Signature Database (DBX) updates, reducing Secure Boot bypass risk for affected vendor-signed UEFI applica...

Nvidia GPU GPUBreach Rowhammer-style page-table corruption privilege-escalation flaw

Vulnerability
H score19 First: 07.04.2026 14:31 Last: 07.04.2026 14:31 Sources 1

About this happening: Researchers demonstrated GPUBreach, a Rowhammer-style weakness in Nvidia GPUs that can corrupt GPU page tables and enable arbitrary read-write access. When pai...

Timeline

  1. 26.08.2026 21:48 2 articles · 14d ago

    University of Toronto researchers notify NVIDIA about GPUThor

    Initial Disclosure

    University of Toronto researchers reported GPUThor to NVIDIA on April 29 after showing that the Rowhammer attack can bypass ECC protections on Ampere-class NVIDIA workstation GPUs, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000 with GDDR6 memory.

    Show sources
  2. 26.08.2026 21:48 1 articles · 14d ago

    NVIDIA issues GPUThor advisory guidance

    Mitigation Patch Update

    NVIDIA published advisory guidance on August 21 after the GPUThor disclosure, recommending SYS-ECC, IOMMU/DMA isolation, GPU error telemetry monitoring, and restricting the sharing or execution of untrusted workloads.

    Show sources
  3. 26.08.2026 21:48 2 articles · 14d ago

    GPUThor paper shows ECC bypass, DoS, and root escalation on NVIDIA GPUs

    Technical Analysis Update

    The GPUThor paper described a non-uniform hammering pattern that avoids GDDR6 Target Row Refresh, reported 387 double-bit errors and two triple-bit errors with ECC enabled, and showed that an ECC-enabled RTX A6000 can reset every two hours and terminate all workloads; the researchers also say corrupting GPU page tables can let an unprivileged CUDA program gain arbitrary memory access and open a root shell on the host system.

    Show sources