By The Hacker News
Publication Date: 2026-08-27 08:13:00
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.
Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM banks for 24 hours each on four Ampere-class cards, inducing bit flips on each.
The following GPUs were tested and found vulnerable –
- RTX A6000 (48 GB GDDR6)
- RTX A5000 (24 GB GDDR6)
- RTX A4500 (20 GB GDDR6)
- RTX A4000 (16 GB GDDR6)
Mounting the attack requires the ability to launch an unprivileged CUDA kernel on the target GPU, either as a co-tenant on a shared card or as untrusted code on a single-tenant machine. The researchers advise avoiding cross-tenant GPU sharing, monitoring ECC error counters, and restricting untrusted CUDA workloads.
“Recently, researchers at the University of Toronto demonstrated a successful Rowhammer exploitation on an NVIDIA A6000 GPU with GDDR6 memory where System-Level ECC was not enabled. In the same paper, the researchers showed that enabling System-Level ECC mitigates the Rowhammer problem,” NVIDIA said in a July 2025 security notice.
That notice followed GPUHammer, the same team’s earlier work, and the first GPU Rowhammer attack demonstrated on NVIDIA hardware, which yielded 16-bit flips per gigabyte on an RTX A6000 and was neutralized…



