New GPUThor attack defeats NVIDIA ECC protection for root access

Summary

A new Rowhammer attack, dubbed GPUThor, has been discovered that can bypass Error-Correcting Code (ECC) protections on NVIDIA GPUs. This vulnerability allows for denial-of-service (DoS) attacks and can escalate privileges to root access.

IFF Assessment

FOE

This attack allows for privilege escalation and denial-of-service, which are detrimental to system security and availability.

Severity

8.8 High (AI Estimated)

The attack allows for privilege escalation to root (High Impact) and can be performed remotely or locally (Attack Vector: Network/Adjacent/Local). It requires specific hardware (NVIDIA GPUs) but can bypass built-in ECC protections, making it a significant threat. The exploitability is high due to the nature of Rowhammer attacks.

Defender Context

This discovery highlights a critical vulnerability in NVIDIA GPUs, potentially impacting systems relying on their ECC protection for integrity. Defenders should monitor for exploit development and vendor advisories regarding patches or mitigations for GPUThor.

Read Full Story →