Skip to content

OSG-SEC-2026-08-25 NVIDIA GPUThor Rowhammer Security Guidance

Dear OSG Security Contacts,

NVIDIA has published updated guidance concerning GPUThor, a Rowhammer attack targeting GPU memory [1]. No CVE has been assigned. Rowhammer is a general class of DRAM attacks and is not specific to NVIDIA; however, NVIDIA Security Notice 5873 provides NVIDIA-specific guidance for its GPU and SoC products.

WHAT ARE THE VULNERABILITIES:

GPUThor is a Rowhammer attack that uses optimized memory-access patterns to induce multiple bit flips in GPU DRAM and overwhelm system-level ECC.
According to the researchers, enabling ECC prevented the previously demonstrated GPUHammer and GPUBreach attacks [2][3][4]. GPUThor extends that research by demonstrating GPU denial of service and root-level privilege escalation against ECC-protected GPUs.
Exploitation requires the ability to execute crafted workloads on a susceptible GPU. NVIDIA advises that properly configured host IOMMU/DMA isolation can block or substantially limit the demonstrated host privilege-escalation path.

IMPACTED VERSIONS:

Risk of successful exploitation from Rowhammer attacks varies based on DRAM device, platform, design specification, and system settings.

Researchers demonstrated bit flips on the following NVIDIA workstation GPUs using GDDR6 memory:

  • NVIDIA RTX A4000
  • NVIDIA RTX A4500
  • NVIDIA RTX A5000
  • NVIDIA RTX A6000

The dynamic OSPool inventory has previously included NVIDIA A10 and RTX 2080 Ti GPUs [5]. Both models use GDDR6 memory [6] [7], the memory class examined by GPUThor. However, neither model is identified by NVIDIA as confirmed vulnerable;

MITIGATION

NVIDIA recommends a layered defense-in-depth approach:
- Enable SYS-ECC on all supported GPUs.
- Enable and verify host IOMMU/DMA isolation.
- Use data center products for higher-assurance environments.
- Monitor correctable and uncorrectable ECC errors, unexpected GPU resets, and row-remapping events.
- Review GPU-sharing, tenancy, and workload-isolation controls.

SYS-ECC should be combined with IOMMU/DMA isolation and should not be treated as a complete mitigation by itself. A GPU driver update alone does not fully mitigate this hardware-level issue. See NVIDIA’s guidance [1] for additional information.

WHAT YOU SHOULD DO:

OSG resource providers operating GPU-enabled worker nodes should inventory their deployed GPU models and memory types and review NVIDIA’s guidance.

Priority should be given to shared or multi-user GPU systems, systems using GDDR6 GPUs, and systems where users can execute arbitrary GPU workloads.
Administrators should verify that SYS-ECC is enabled where supported and that the host IOMMU is enabled and actively enforcing DMA isolation.

REFERENCES

[1] https://nvidia.custhelp.com/app/answers/detail/a_id/5873
[2] https://gputhor.com/
[3] https://gpubreach.ca/
[4] https://osg-htc.org/security/vulns/OSG-SEC-2026-04-06/
[5] https://portal.osg-htc.org/documentation/htc_workloads/specific_resource/gpu-jobs/
[6] https://www.nvidia.com/content/nvidiaGDC/zz/en_ZZ/geforce/graphics-cards/rtx-2080-ti.html
[7] https://www.nvidia.com/content/dam/en-zz/Solutions/Data-Center/a10/pdf/datasheet-new/nvidia-a10-datasheet.pdf

Please contact the OSG security team at [email protected] if you have any questions or concerns.

OSG Security Team.