Bleepingcomputer GPUBreach: New GPU Rowhammer Attack Enables Full System Compromise
Article Content
- •GPUBreach allows full system compromise via GPU Rowhammer attacks without disabling IOMMU.
- •The attack exploits memory-safety vulnerabilities in Nvidia drivers and corrupts GPU page tables.
- •Sensitive data, including cryptographic keys, can be manipulated or extracted through this exploit.
Researchers from the University of Toronto have unveiled a new attack named GPUBreach that exploits Rowhammer vulnerabilities in Nvidia's GDDR6 memory. This attack allows privilege escalation from an unprivileged CUDA kernel to root access on the host system without needing to disable the Input-Output Memory Management Unit (IOMMU). By corrupting GPU page tables, attackers can gain arbitrary read/write access to GPU memory and subsequently exploit memory-safety bugs in the Nvidia driver to achieve full system compromise. The attack can manipulate sensitive data, including cryptographic keys and machine learning model weights, significantly impacting AI workloads. The findings will be presented at the IEEE Symposium on Security & Privacy on April 13, 2026. Nvidia has acknowledged the issue and may update its security advisory, while Google awarded the researchers a $600 bug bounty for their discovery. Despite the severity, the current risk level is considered manageable by some industry players.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Continue Reading
GPUThor Attack Bypasses ECC on NVIDIA GPUs for Root Access Researchers from the University of Toronto have revealed a new Rowhammer attack named GPUThor that can bypass ECC protections on NVIDIA GPUs, specifically targeting Ampere-class models like the RTX A4000 and A6000. This attack allows for denial-of-service (DoS) and root-level privilege escalation by corrupting GPU…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…