Find notable cyber news and cases, enriched with sources, timelines, and signals.

NVIDIA GPUThor mitigation advisory

Advisory/Mitigation
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

University of Toronto researchers disclosed GPUThor, a Rowhammer attack against NVIDIA workstation GPUs with GDDR6 memory that can bypass ECC, trigger denial-of-service, and enable host root escalation. NVIDIA later issued GPUThor hardening guidance on August 21 after being notified on April 29, 2026, recommending SYS-ECC, IOMMU/DMA isolation, GPU error telemetry monitoring, and restricting untrusted CUDA workloads. The affected models tested were RTX A4000, RTX A4500, RTX A5000, and RTX A6000. The researchers also reported double-bit errors and incorrect triple-bit error repairs, and said a locally owned RTX A6000 could be driven into a DoS state with ECC enabled.

Related Happenings

NVIDIA Ampere-class GPUs GPUThor Rowhammer ECC bypass privilege-escalation flaw

Vulnerability
H score26 First: 26.08.2026 21:48 Last: 26.08.2026 21:48 Sources 1

How related: Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.

About this happening: GPUThor is a Rowhammer vulnerability affecting NVIDIA workstation GPUs with GDDR6 memory that can defeat ECC and enable denial-of-service plus host root pr...

Bit2Watt GPU power modulation research on grid destabilization

Technical Analysis
H score22 First: 21.07.2026 14:24 Last: 21.07.2026 14:24 Sources 1

About this happening: Researchers published Bit2Watt, showing that ordinary cloud GPU workloads can be shaped into kilohertz-range power oscillations that may destabilize grid behavior...

Microsoft Windows 11 update rollout blocked on Dell devices over driver incompatibility

Service Disruption
H score1 First: 15.07.2026 11:26 Last: 15.07.2026 11:26 Sources 1

About this happening: Microsoft is blocking KB5101650 on some Dell devices after a driver incompatibility caused unexpected shutdowns and other stability problems. The hold affects Window...

UEFI shim Secure Boot bypass (multiple vulnerabilities)

Vulnerability
H score1 First: 14.07.2026 15:46 Last: 14.07.2026 15:46 Sources 1

About this happening: Researchers identified 11 old, Microsoft-signed UEFI shim bootloaders that can bypass Secure Boot on systems trusting the Microsoft Corporation UEFI CA 2011 certificat...

Latest development: 15.07.2026 17:00

Microsoft revoked the vulnerable Microsoft-signed UEFI shim bootloaders in the dbx update shipped with the June 9 Patch Tuesday, closing the Secure Boot bypass tracked as CVE-2026-8863 and CVE-2026-10797. Windows machines should update automatically, while Linux users can pull the revocation through the Linux Vendor Firmware Service.

Nvidia GPU GPUBreach Rowhammer-style page-table corruption privilege-escalation flaw

Vulnerability
H score19 First: 07.04.2026 14:31 Last: 07.04.2026 14:31 Sources 1

About this happening: Researchers demonstrated GPUBreach, a Rowhammer-style weakness in Nvidia GPUs that can corrupt GPU page tables and enable arbitrary read-write access. When pai...

Timeline

  1. 26.08.2026 21:48 3 articles · 14d ago

    NVIDIA publishes GPUThor hardening guidance

    Mitigation Patch Update

    NVIDIA published guidance for GPUThor on August 21 after researchers reported the findings on April 29. The advisory recommends enabling SYS-ECC and IOMMU/DMA isolation, monitoring GPU error telemetry, and restricting the sharing or execution of untrusted CUDA workloads to reduce the risk of ECC bypass, denial of service, and privilege escalation on vulnerable NVIDIA GPU systems.

    Show sources
  2. 26.08.2026 21:48 1 articles · 14d ago

    University of Toronto researchers demonstrate GPUThor on Ampere-class NVIDIA GPUs

    Technical Analysis Update

    University of Toronto researchers disclosed GPUThor and showed that the Rowhammer technique can bypass ECC protections on Ampere-class NVIDIA workstation GPUs with GDDR6 memory, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000. They also reported that the attack can generate double-bit errors and incorrect triple-bit error repairs, and that repeated hammering can drive an ECC-enabled RTX A6000 into a denial-of-service state that resets every two hours and terminates all workloads.

    Show sources