GPUThor attack bypasses NVIDIA ECC protection to enable root access
University of Toronto researchers disclosed GPUThor, a Rowhammer-style attack that bypasses error-correcting code (ECC) on NVIDIA GPUs and enables denial-of-service and root-level privilege escalation.
Source: BleepingComputer · August 26, 2026 at 11:31 PM · AI-assisted report
Single-sourceKUALA LUMPUR, 27 AUGUST 2026 —
New GPU Attack Bypasses NVIDIA ECC Protection, Raising Security Risks for Malaysian AI, Cloud Sectors
Market Impact
KUALA LUMPUR – A newly disclosed Rowhammer-style attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) conditions and potential root-level privilege escalation, according to research from the University of Toronto.
The attack exploits memory bit-flipping vulnerabilities in NVIDIA’s Ampere-class GPUs, including widely used models such as the RTX A4000, RTX A4500, RTX A5000, and RTX A6000—commonly deployed in AI training and cloud infrastructure. Rowhammer attacks involve repeatedly accessing memory rows to induce bit flips, which can corrupt data and compromise security.
Unlike previous attacks like GPUHammer, GPUThor achieves higher bit-flip rates—between 72,000 and 377,000 flips per GB—by exploiting undocumented GPU behaviors to evade Target Row Refresh (TRR) mitigations in GDDR6 memory. With ECC disabled, the attack can flip bits within 1.1 minutes, compared to 21.9 hours with prior methods. Even with ECC enabled, GPUThor triggered 387 double-bit errors and two triple-bit errors, leading to data corruption.
Researchers demonstrated that GPUThor could force an ECC-enabled RTX A6000 to reset every two hours, disrupting workloads and eventually rendering the GPU unusable. A more critical risk is privilege escalation, where an unprivileged CUDA program could corrupt GPU page tables, granting arbitrary memory access and enabling a root shell on the host system.
While NVIDIA’s SECDED ECC mitigates single-bit errors, GPUThor’s ability to bypass these protections raises concerns for AI and cloud providers in Malaysia, where GPU acceleration is critical for sectors like finance, healthcare, and smart manufacturing. The attack also affects server-class Ampere GPUs (A100) and may impact newer Blackwell GPUs, though resilience features like RAS Repair increase attack difficulty.
NVIDIA was notified of the vulnerability on April 29, and the company issued an advisory on August 21, recommending mitigations such as enabling SYS-ECC and IOMMU/DMA isolation, monitoring GPU error telemetry, and restricting untrusted workloads. However, the researchers noted that no bit flips were observed on GDDR6X or HBM2e GPUs under the same attack patterns, suggesting variability in risk across GPU models.
For Malaysian businesses leveraging NVIDIA GPUs in AI model training, data centers, or cloud services, the findings underscore the need for enhanced monitoring and access controls. The researchers recommend avoiding cross-tenant GPU sharing, tracking ECC error counters, and limiting execution of untrusted CUDA workloads. Long-term solutions may require stronger multi-bit ECC and hardware-level defenses in future GPU generations.
The disclosure comes as Malaysia accelerates its AI and digital economy initiatives, with NVIDIA GPUs playing a key role in public sector and enterprise deployments. While NVIDIA’s advisory provides interim guidance, the GPUThor attack highlights the evolving threat landscape for memory-hardened hardware in high-performance computing environments.
Details not yet available on whether Malaysian organizations have been targeted or if patches have been deployed. NVIDIA has not responded to requests for comment on regional impact.
Related: NVIDIA · Kuala Lumpur