GPUThor Rowhammer Attack Defeats ECC on NVIDIA RTX A6000 GPUs, Enables Host Root Access
What Happened — Academic researchers from the University of Toronto disclosed “GPUThor,” a Rowhammer technique that targets GDDR6 memory on NVIDIA RTX A6000 workstation GPUs. The attack defeats NVIDIA’s recommended ECC mitigation, allowing denial‑of‑service and privilege escalation to a root shell on the host system.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a gap in SOC 2 CC6.1 (System Operations) and CC7.1 (Risk Management) where hardware‑level mitigations must be continuously monitored and evidenced.
- Requires documented proof that firmware patches or configuration changes are applied, a core element of continuous‑compliance programs.
- Highlights the need for control mapping that ties emerging hardware vulnerabilities to audit‑ready controls and evidence collection.
Who Is Affected — Organizations that rely on high‑performance GPUs for AI/ML, scientific computing, media rendering, or cloud‑based GPU services.
Recommended Actions —
- Add the GPUThor vulnerability to your risk register and map it to SOC 2 CC6.1 and CC7.1 controls.
- Deploy NVIDIA’s forthcoming firmware patches or mitigations immediately.
- Implement continuous monitoring of GPU error logs and ECC status to detect anomalous activity.
- Capture and retain evidence of patch deployment and monitoring as part of your audit artifact set.
Source: The Hacker News
Technical Notes — The attack leverages a Rowhammer fault in GDDR6 memory, bypassing ECC and NVIDIA’s software‑level mitigations. No CVE has been assigned yet; the researchers plan to coordinate disclosure with NVIDIA. The exploit can lead to DoS and full host compromise, exposing any data processed on the affected system.