Rowhammer attack targets NVIDIA GPUs with GDDR6

New research shows Rowhammer exploits can target NVIDIA GPUs using GDDR6 memory and extend beyond the graphics subsystem into host CPU memory. The attacks can corrupt GPU page tables and lead to full system compromise.

Rowhammer attacks are no longer limited to CPUs and DDR memory. New research indicates that NVIDIA GPUs using GDDR6 are also vulnerable, and the impact reaches beyond graphics hardware into the host system. Two independent teams, GDDRHammer and GeForge, developed working exploits that use Rowhammer-induced bit-flips in NVIDIA GPUs to gain complete control over the host CPU’s memory.

The attack applies to some NVIDIA GPU models spanning the Ampere to Ada Lovelace families. An attacker who succeeds can read and write anything stored in the machine’s main memory. Both teams introduced Rowhammer techniques tailored to GPU architecture, and these methods achieved a significantly higher rate of bit-flips on GDDR6 memory than previous approaches.

The key stage in both exploit chains targets the GPU memory allocator. Controlled bit-flips are used to corrupt the GPU’s page tables, and once those page tables are compromised, the attacker gains arbitrary read and write access to CPU memory. That collapses the security boundary between the graphics subsystem and the rest of the machine, enabling a full system compromise and root access without interacting with privileged software paths.

The affected GPUs include the GeForce RTX 3060, which experienced 1,171 bit-flips, and the RTX 6000 ‘Ada’ GPU, which saw 202 bit-flips from the attack. The findings show that the fragile nature of GDDR6 memory can be exploited in ways that directly compromise the CPU host, turning a long-known DRAM weakness into a broader platform security problem.

82

Impact Score

Google Vids opens free video generation to all Google users

Google has made Google Vids available to anyone with a Google account, adding free access to video generation with its latest models. The move expands Google’s end-to-end video workflow and increases pressure on rivals that charge for similar tools.

Court warns against chatbot legal advice in Heppner case

A federal court found that chats with a publicly available generative Artificial Intelligence tool were not protected by attorney-client privilege or the work-product doctrine. The ruling highlights litigation risks when executives or employees use chatbots for legal guidance without lawyer supervision.

Newsom orders California to weigh Artificial Intelligence harms in contract rules

Gov. Gavin Newsom has signed an executive order directing California agencies to account for potential Artificial Intelligence harms in state contracting while expanding approved use of generative tools across government. The move follows a dispute involving Anthropic and reflects a broader split between California and the Trump administration on Artificial Intelligence oversight.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.