Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Burnham electrified the Labour party by talking about electoral reform – now he needs to act on it | Polly Toynbee

    August 28, 2026

    What does the Meta settlement mean for the UK? Five things we learned

    August 28, 2026

    New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

    August 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Burnham electrified the Labour party by talking about electoral reform – now he needs to act on it | Polly Toynbee
    • What does the Meta settlement mean for the UK? Five things we learned
    • New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
    • Ethereum’s plan to triple network speed could silently break millions of existing smart contracts
    • Scientists discover a brain “brake” that can shut down chronic pain
    • Empoderando a las comunidades guatemaltecas afectadas por el plástico
    • Dear culture-war motorists, look to the future. We’ll all be driving at 20mph soon | Christian Wolmar
    • Norway’s King Harald dies leaving stormy succession over crown princess’s Epstein links | Norway
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 28, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.

    Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM banks for 24 hours each on four Ampere-class cards, inducing bit flips on each.

    The following GPUs were tested and found vulnerable –

    • RTX A6000 (48 GB GDDR6)
    • RTX A5000 (24 GB GDDR6)
    • RTX A4500 (20 GB GDDR6)
    • RTX A4000 (16 GB GDDR6)

    Mounting the attack requires the ability to launch an unprivileged CUDA kernel on the target GPU, either as a co-tenant on a shared card or as untrusted code on a single-tenant machine. The researchers advise avoiding cross-tenant GPU sharing, monitoring ECC error counters, and restricting untrusted CUDA workloads.

    “Recently, researchers at the University of Toronto demonstrated a successful Rowhammer exploitation on an NVIDIA A6000 GPU with GDDR6 memory where System-Level ECC was not enabled. In the same paper, the researchers showed that enabling System-Level ECC mitigates the Rowhammer problem,” NVIDIA said in a July 2025 security notice.

    That notice followed GPUHammer, the same team’s earlier work, and the first GPU Rowhammer attack demonstrated on NVIDIA hardware, which yielded 16-bit flips per gigabyte on an RTX A6000 and was neutralized once ECC was enabled.

    Cybersecurity

    What GPUThor adds is non-uniform hammering, where the aggressor row next to the victim is activated far more often than the decoy rows used to swamp the memory’s Target Row Refresh (TRR) defense. Prior GPU attacks activated aggressor and decoy rows at roughly the same rate.

    The researchers found that repeated accesses issued inside a single warp, the group of 32 threads a GPU runs in lockstep, are merged at the memory controller into a single DRAM activation.

    Accesses issued from different warps to different cache lines within the same row survive as separate activations, and the hammering kernels distribute them accordingly.

    They also reported in the GPUThor paper that TRR on these GDDR6 parts likely applies about once every 72 refresh intervals rather than once per interval, and built a six-interval pattern around that schedule.

    Across the four cards, the campaigns produced 72,000 to 377,000 bit flips per gigabyte with ECC disabled.

    The RTX A5000 was the most susceptible at 377,552 flips per gigabyte, which is 23,597 times GPUHammer’s 16 flips per gigabyte and roughly 500 times the 758 flips per gigabyte reported for GDDRHammer, the strongest prior GPU Rowhammer attack.

    The paper places the A5000 rate close to the roughly 550,000 flips per gigabyte reached by Blacksmith, which established non-uniform hammering on DDR4 as a route past in-DRAM defenses.

    At a 16-byte granularity, the campaigns turned up 387 double-bit flips and two triple-bit flips across the four cards with ECC disabled, with the A5000 accounting for 306 of the double-bit flips and both triple-bit flips.

    The single-error-correct, double-error-detect (SECDED) ECC on these GPUs corrects one flipped bit in a protected chunk and detects two, and the researchers found that it mis-corrects three, resulting in silent data corruption (SDC).

    With ECC enabled on a locally owned RTX A6000, one bank of hammering produced 11 detectable, uncorrectable errors (DUE) and one SDC over a day, an average of one DUE every two hours. Each DUE aborts all kernels running on the card, leaving it unusable until a reset.

    For the escalation itself, the researchers reused the exploit code from GPUBreach, their earlier GPU page-table privilege escalation research.

    Page tables are first massaged into a vulnerable row. The neighboring rows are then hammered to corrupt the page-frame number of an entry. A second kernel reaches memory outside the process through the tampered entry.

    Using the triple-bit SDC, the researchers obtained root on the host with the IOMMU enabled. Using a double-bit DUE, they achieved host-side privilege escalation on systems where the IOMMU is disabled. A page-table entry is repointed at CPU memory. The process credential structure is then overwritten.

    “Moreover, we discover that even double-bit DUEs are exploitable, since DUEs are serviced lazily in NVIDIA GPUs, leaving a ~10 ms time window between DUE detection and the GPU being killed, during which the corrupted data is consumed by the attacker’s GPU kernel,” the researchers said.

    Locating exploitable multi-bit errors without setting off a DUE took about four days on the A6000. An end-to-end privilege escalation that took 21.9 hours on that card was completed in 1.1 minutes with GPUHammer’s patterns and in 1.1 minutes with GPUThor’s.

    The same patterns produced no bit flips on the other NVIDIA parts tested, including an A10, an L4, and an L40 on GDDR6, an RTX 4090 on GDDR6X, and an A30 on HBM2e.

    “We also tested other memory types (see Appendix D), including HBM, GDDR6X, and newer-generation GDDR6 on NVIDIA GPUs, and did not observe any bit flips on them. This is likely due to differing TRR implementations in these memories compared to the A4000-A6000 GPUs, which make GPUThor’s patterns unsuccessful,” the researchers said.

    Cybersecurity

    The A100 and H100 were outside the tested set.

    Server-class Ampere GPUs and newer carry Error Containment and Dynamic Page Offlining, which confine a fault to the triggering application, but they still rely on SECDED-level ECC, and the researchers said an SDC-based escalation could still work against them. RAS Repair on some Blackwell GPUs makes the DUE-based route more time-consuming without preventing it, they said.

    GPUThor was reported to NVIDIA on April 29, 2026, and to Google, Microsoft, and AWS. The findings were then subject to an embargo that ran until August 25, 2026. NVIDIA released a security notice with guidance at the end, the researchers said.

    GPUThor does not carry a CVE identifier, and no in-the-wild exploitation has been reported as of August 27, 2026. No patch addresses the attack, and the researchers said a complete fix would require stronger multi-bit error correction and in-DRAM defenses, such as Refresh Management or Per-Row Activation Counting, in future GPUs.

    The attack code is due for public release on November 15, 2026, the opening day of the ACM Conference on Computer and Communications Security, where the paper will be presented.

    The Hacker News contacted NVIDIA for comment on whether ECC remains a sufficient mitigation and the University of Toronto researchers for further detail; neither had responded by publication.

    “We used these to crash GPUs and to escalate privileges with ECC enabled. ECC still raises the bar and remains worth enabling, but it can no longer be treated as a sufficient defense,” the researchers said on the GPUThor project site.

    A6000 access Defeats ECC gain GPUThor Host Nvidia Root Rowhammer RTX
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

    Indigenous water systems gain ground as climate pressures intensify in Bolivia

    Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services

    What the Data Says About AI in Security Operations in 2026

    US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

    Agentic AI Risks, CVE Program Concerns Permeate Black Hat 2026

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Burnham electrified the Labour party by talking about electoral reform – now he needs to act on it | Polly Toynbee

    August 28, 2026

    What does the Meta settlement mean for the UK? Five things we learned

    August 28, 2026

    New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

    August 28, 2026

    Ethereum’s plan to triple network speed could silently break millions of existing smart contracts

    August 28, 2026
    Latest Posts

    NASA’s Curiosity Discovers a Field of Martian Polygons

    July 29, 2026

    As crypto perpetual futures boom, Ethereum’s role is shifting

    July 29, 2026

    Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Burnham electrified the Labour party by talking about electoral reform – now he needs to act on it | Polly Toynbee

    August 28, 2026

    What does the Meta settlement mean for the UK? Five things we learned

    August 28, 2026

    New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

    August 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.