A New Rowhammer Vulnerability Exploits NVIDIA’s RTX A6000, Putting Sensitive Data at Risk
Researchers have discovered a fresh Rowhammer vulnerability affecting NVIDIA’s high-end graphics processing unit (GPU), the RTX A6000. Dubbed “GPUThor,” this flaw allows attackers to bypass Error-Correcting Code (ECC) memory protection, gaining host root access and compromising sensitive data.
The GPUThor exploit leverages the Rowhammer effect, a phenomenon where repeated accesses to adjacent memory locations can alter bits in a targeted area of memory. This weakness is particularly concerning on systems employing ECC memory, which are designed to detect and correct errors. However, by carefully timing their attacks, hackers can exploit this vulnerability even when ECC is enabled.
NVIDIA’s RTX A6000, as well as other similar GPUs, rely on the Rowhammer effect to manage memory allocation. By manipulating the memory access patterns, an attacker can create a situation where the targeted area of memory is repeatedly accessed by adjacent locations, inducing bit flips and ultimately breaching ECC protection.
The GPUThor vulnerability poses significant risks for organizations utilizing high-end NVIDIA graphics processing units in their data centers or server infrastructure. With host root access granted through this exploit, attackers could potentially breach sensitive areas of the system, including administrative interfaces, configuration files, and encrypted data storage.
While this latest Rowhammer discovery highlights ongoing vulnerabilities in modern hardware, researchers emphasize that it is not a straightforward attack vector for most users. However, it underscores the importance of continued vigilance and thorough testing for critical infrastructure components to mitigate potential risks.
The GPUThor exploit also serves as a reminder for IT administrators to prioritize software updates and security patches for high-end GPUs. Furthermore, experts recommend conducting regular system audits and vulnerability assessments to ensure that hardware-specific vulnerabilities are addressed promptly.
Source: The Hacker News — 2026-08-27