New Rowhammer attacks give complete control of machines running Nvidia GPUs



So where do we go now?

The researchers said that both the RTX 3060 and RTX 6000 cards are vulnerable. Changing BIOS defaults to enable IOMMU closes the vulnerability, they said. Short for input-output memory management unit, IOMMU maps device-visible virtual addresses to physical addresses on the host memory. It can be used to make certain parts of memory off-limits.

“In the context of our attack, an IOMMU can simply restrict the GPU from accessing sensitive memory locations on the host,” Kwong explained. “IOMMU is, however, disabled by default in the BIOS to maximize compatibility and because enabling the IOMMU comes with a performance penalty due to the overhead of the address translations.”

A separate mitigation is to enable Error Correcting Codes (ECC) on the GPU, something Nvidia allows to be done using a command line. Like IOMMU, enabling ECC incurs some performance overhead because it reduces the overall amount of available workable memory. Further, some Rowhammer attacks can overcome ECC mitigations.

GPU users should understand that the only cards known to be vulnerable to Rowhammer are the RTX 3060 and RTX 6000 from the Ampere generation, which were introduced in 2020. It wouldn’t be surprising if newer generations of graphics cards from Nvidia and others are susceptible to the same types of attacks, but because the pace of academic research typically lags far behind the faster speed of product rollouts, there’s no way now to know.

Top-tier cloud platforms typically provide security levels that go well beyond those available by default on hobbyist and consumer machines. Another thing to remember: There are no known instances of Rowhammer attacks ever being actively used in the wild.

The true value of the research is to put GPU makers and users alike on notice that Rowhammer attacks on these platforms have the potential to upend security in serious ways. More information about GDDRHammer and GeForge is available here.



Source link

  • Related Posts

    The Best Samsung Galaxy S26 Cases (2026): S26, S26+, and S26 Ultra

    Other Cases to Consider Photograph: Louryn Strampe Spigen Tough Armor and Nano Pop MagFit Cases: These affordable cases both look and perform well for the price. The Nano Pop case…

    Google now lets you direct avatars through prompts in its Vids app

    Google on Thursday added new features to its video editor app Vids, including directing and customizing avatars through text prompts, Veo 3.1 support, the ability to export videos to YouTube,…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Strong Jobs Numbers Make the Fed’s Job Easier

    The Best Samsung Galaxy S26 Cases (2026): S26, S26+, and S26 Ultra

    The Best Samsung Galaxy S26 Cases (2026): S26, S26+, and S26 Ultra

    First Jewish-Canadian mission to Cuba in seven years

    First Jewish-Canadian mission to Cuba in seven years

    Canada Gazette – Part I, June 14, 2025, volume 159, number 24

    Hyundai recalls some Canadian vehicles due to seatbelt issue

    Hyundai recalls some Canadian vehicles due to seatbelt issue

    Enzo Fernandez: Chelsea midfielder dropped after ‘crossing a line’, says manager Liam Rosenior

    Enzo Fernandez: Chelsea midfielder dropped after ‘crossing a line’, says manager Liam Rosenior