← Blog · · df00tech

GPUThor: New Rowhammer Variant Bypasses ECC to Attack NVIDIA GPUs

security-news technique

Researchers have disclosed a new Rowhammer-class attack, dubbed GPUThor, that reportedly defeats error-correcting code (ECC) protections on NVIDIA GPUs. According to the report, the attack can be used to trigger denial-of-service conditions and, more seriously, achieve root-level privilege escalation. Details on the specific GPU models, driver versions, and exploitation prerequisites affected are not yet fully clear from initial reporting.

Why It Matters

Rowhammer-style bit-flipping attacks have historically targeted DRAM on CPUs, and ECC has been considered a meaningful mitigation. GPUThor's significance is that it reportedly bypasses ECC specifically on GPU memory, which undermines an assumption many organizations rely on for GPU-accelerated workloads — including cloud GPU rental, virtualized/multi-tenant GPU environments, AI/ML training infrastructure, and any system where GPUs process untrusted or multi-tenant data. If root-level privilege escalation is achievable from a GPU-level primitive, this could have serious implications for GPU sandboxing and isolation guarantees in shared-tenancy environments.

What Defenders Should Watch For

  • Monitor NVIDIA security advisories and driver/firmware update channels closely for patches or mitigations addressing this issue.
  • For multi-tenant or cloud GPU environments, review isolation boundaries and consider whether workloads assume ECC as a hard security guarantee.
  • Watch for unusual GPU memory error rates, unexpected driver crashes, or anomalous privilege changes on systems with GPU-accelerated workloads, as potential signals of exploitation attempts.
  • Where feasible, restrict which users or workloads have direct hardware-level access to GPUs, particularly in shared infrastructure.
  • Track vendor guidance on whether physical proximity, specific memory types, or particular GPU generations are prerequisites for the attack, as this will shape exposure assessments.

This is developing intelligence based on a single news report, and technical specifics (affected hardware scope, proof-of-concept availability, and vendor response) are still emerging. We will monitor for follow-up disclosures and vendor advisories. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.