Briefing

New Rowhammer Attacks Grant Full Control Over NVIDIA GPUs and Host CPUs

security
by Bruce Schneier ·

Enable IOMMU in BIOS and apply NVIDIA firmware patches to mitigate rowhammer vulnerabilities.

What to do now

Enable IOMMU in BIOS and apply NVIDIA firmware updates; monitor for vendor patches addressing rowhammer.

Summary

Two independent research teams have demonstrated that rowhammer attacks on NVIDIA’s Ampere GPUs can induce GDDR bitflips, giving attackers arbitrary read/write access to the host CPU memory and full system compromise. The attacks require the IOMMU to be disabled, which is the default BIOS setting on many systems. A third attack, targeting the RTX A6000, achieves privilege escalation to a root shell even when IOMMU is enabled. The GeForge technique manipulates the last‑level page directory, causing 1,171 bitflips on an RTX 3060 and 202 on an RTX 6000, and corrupts GPU page tables in GDDR6 to gain host CPU privileges. Both GDDRHammer and GeForge can target the RTX 6000, and the GeForge proof‑of‑concept on the RTX 3060 concludes by opening a root shell. These findings expose a serious hardware‑level vulnerability that can be exploited to run arbitrary code on the host machine.

The research highlights that GPU rowhammer can now reach beyond the GPU, compromising the entire system. The attacks exploit memory management weaknesses that allow bit flips in GPU memory to propagate to CPU memory, effectively bypassing traditional isolation mechanisms.

Key changes

  • Two teams proved rowhammer on Ampere GPUs can flip GDDR bits and grant full CPU memory access
  • The attacks require IOMMU disabled, the default BIOS setting
  • A third attack on RTX A6000 achieves root shell even with IOMMU enabled
  • GeForge manipulates the last‑level page directory, causing 1,171 bitflips on RTX 3060 and 202 on RTX 6000
  • Both GDDRHammer and GeForge can target the RTX 6000
  • The exploits corrupt GPU page tables in GDDR6 to gain host CPU privileges
  • Root shell is achieved in the RTX 3060 proof‑of‑concept
  • The vulnerability allows arbitrary read/write of host memory

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting