NVIDIA Ampere-class GPUs GPUThor Rowhammer ECC bypass privilege-escalation flaw
Vulnerability
Summary
Hide ▲
Show ▼
GPUThor is a Rowhammer vulnerability affecting NVIDIA workstation GPUs with GDDR6 memory that can defeat ECC and enable denial-of-service plus host root privilege escalation. University of Toronto researchers said they tested RTX A6000, RTX A5000, RTX A4500, and RTX A4000 cards, used non-uniform hammering to bypass Target Row Refresh (TRR), and reported April 29, 2026 notification to NVIDIA. NVIDIA later issued guidance recommending SYS-ECC, IOMMU/DMA isolation, GPU error telemetry monitoring, and restricting untrusted CUDA workloads. The researchers said there is no CVE and no patch for the attack.
Related Happenings
NVIDIA GPUThor mitigation advisory
Advisory/Mitigation
H score29
First: 26.08.2026 21:48
Last: 26.08.2026 21:48
Sources 1
How related:
The researchers reported their findings to NVIDIA on April 29, and on August 21, the company published an advisory providing guidance.
About this happening:
University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA workstation GPUs with GDDR6 memory that can bypass ECC, trigger denial...
NVIDIA GPUThor mitigation advisory
Advisory/MitigationHow related: The researchers reported their findings to NVIDIA on April 29, and on August 21, the company published an advisory providing guidance.
About this happening: University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA workstation GPUs with GDDR6 memory that can bypass ECC, trigger denial...
Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)
Vulnerability
H score10
First: 11.08.2026 15:05
Last: 11.08.2026 15:05
Sources 1
About this happening:
CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code...
Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)
VulnerabilityAbout this happening: CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code...
Bit2Watt GPU power modulation research on grid destabilization
Technical Analysis
H score22
First: 21.07.2026 14:24
Last: 21.07.2026 14:24
Sources 1
About this happening:
Researchers published Bit2Watt, showing that ordinary cloud GPU workloads can be shaped into kilohertz-range power oscillations that may destabilize grid behavior...
Bit2Watt GPU power modulation research on grid destabilization
Technical AnalysisAbout this happening: Researchers published Bit2Watt, showing that ordinary cloud GPU workloads can be shaped into kilohertz-range power oscillations that may destabilize grid behavior...
CERT/CC UEFI DBX mitigation for vendor-signed applications
Advisory/Mitigation
H score28
First: 19.06.2026 21:33
Last: 19.06.2026 21:33
Sources 1
About this happening:
CERT/CC issued mitigation guidance to apply UEFI Forbidden Signature Database (DBX) updates, reducing Secure Boot bypass risk for affected vendor-signed UEFI applica...
CERT/CC UEFI DBX mitigation for vendor-signed applications
Advisory/MitigationAbout this happening: CERT/CC issued mitigation guidance to apply UEFI Forbidden Signature Database (DBX) updates, reducing Secure Boot bypass risk for affected vendor-signed UEFI applica...
Nvidia GPU GPUBreach Rowhammer-style page-table corruption privilege-escalation flaw
Vulnerability
H score19
First: 07.04.2026 14:31
Last: 07.04.2026 14:31
Sources 1
About this happening:
Researchers demonstrated GPUBreach, a Rowhammer-style weakness in Nvidia GPUs that can corrupt GPU page tables and enable arbitrary read-write access. When pai...
Nvidia GPU GPUBreach Rowhammer-style page-table corruption privilege-escalation flaw
VulnerabilityAbout this happening: Researchers demonstrated GPUBreach, a Rowhammer-style weakness in Nvidia GPUs that can corrupt GPU page tables and enable arbitrary read-write access. When pai...
Timeline
-
26.08.2026 21:48 2 articles · 14d ago
University of Toronto researchers notify NVIDIA about GPUThor
Initial DisclosureUniversity of Toronto researchers reported GPUThor to NVIDIA on April 29 after showing that the Rowhammer attack can bypass ECC protections on Ampere-class NVIDIA workstation GPUs, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000 with GDDR6 memory.
Show sources
- New GPUThor attack defeats NVIDIA ECC protection for root access — www.bleepingcomputer.com — 26.08.2026 21:48
- New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access — thehackernews.com — 27.08.2026 11:13
-
26.08.2026 21:48 1 articles · 14d ago
NVIDIA issues GPUThor advisory guidance
Mitigation Patch UpdateNVIDIA published advisory guidance on August 21 after the GPUThor disclosure, recommending SYS-ECC, IOMMU/DMA isolation, GPU error telemetry monitoring, and restricting the sharing or execution of untrusted workloads.
Show sources
- New GPUThor attack defeats NVIDIA ECC protection for root access — www.bleepingcomputer.com — 26.08.2026 21:48
-
26.08.2026 21:48 2 articles · 14d ago
GPUThor paper shows ECC bypass, DoS, and root escalation on NVIDIA GPUs
Technical Analysis UpdateThe GPUThor paper described a non-uniform hammering pattern that avoids GDDR6 Target Row Refresh, reported 387 double-bit errors and two triple-bit errors with ECC enabled, and showed that an ECC-enabled RTX A6000 can reset every two hours and terminate all workloads; the researchers also say corrupting GPU page tables can let an unprivileged CUDA program gain arbitrary memory access and open a root shell on the host system.
Show sources
- New GPUThor attack defeats NVIDIA ECC protection for root access — www.bleepingcomputer.com — 26.08.2026 21:48
- New GPUThor attack defeats NVIDIA ECC protection for root access — www.bleepingcomputer.com — 26.08.2026 21:48