Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

GPUThor Rowhammer Attack Defeats ECC on NVIDIA RTX A6000 GPUs, Enables Host Root Access

Researchers have demonstrated GPUThor, a Rowhammer technique that bypasses ECC on NVIDIA RTX A6000 GPUs, allowing denial‑of‑service and privilege escalation to a root shell. The flaw highlights the need for SOC 2‑aligned control mapping and continuous evidence of hardware‑level mitigations.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

GPUThor Rowhammer Attack Defeats ECC on NVIDIA RTX A6000 GPUs, Enables Host Root Access

What Happened — Academic researchers from the University of Toronto disclosed “GPUThor,” a Rowhammer technique that targets GDDR6 memory on NVIDIA RTX A6000 workstation GPUs. The attack defeats NVIDIA’s recommended ECC mitigation, allowing denial‑of‑service and privilege escalation to a root shell on the host system.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a gap in SOC 2 CC6.1 (System Operations) and CC7.1 (Risk Management) where hardware‑level mitigations must be continuously monitored and evidenced.
  • Requires documented proof that firmware patches or configuration changes are applied, a core element of continuous‑compliance programs.
  • Highlights the need for control mapping that ties emerging hardware vulnerabilities to audit‑ready controls and evidence collection.

Who Is Affected — Organizations that rely on high‑performance GPUs for AI/ML, scientific computing, media rendering, or cloud‑based GPU services.

Recommended Actions —

  • Add the GPUThor vulnerability to your risk register and map it to SOC 2 CC6.1 and CC7.1 controls.
  • Deploy NVIDIA’s forthcoming firmware patches or mitigations immediately.
  • Implement continuous monitoring of GPU error logs and ECC status to detect anomalous activity.
  • Capture and retain evidence of patch deployment and monitoring as part of your audit artifact set.

Source: The Hacker News

Technical Notes — The attack leverages a Rowhammer fault in GDDR6 memory, bypassing ECC and NVIDIA’s software‑level mitigations. No CVE has been assigned yet; the researchers plan to coordinate disclosure with NVIDIA. The exploit can lead to DoS and full host compromise, exposing any data processed on the affected system.

📰 Original Source
https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →