New Rowhammer attacks give complete control of machines running Nvidia GPUs



So where do we go now?

The researchers said that both the RTX 3060 and RTX 6000 cards are vulnerable. Changing BIOS defaults to enable IOMMU closes the vulnerability, they said. Short for input-output memory management unit, IOMMU maps device-visible virtual addresses to physical addresses on the host memory. It can be used to make certain parts of memory off-limits.

“In the context of our attack, an IOMMU can simply restrict the GPU from accessing sensitive memory locations on the host,” Kwong explained. “IOMMU is, however, disabled by default in the BIOS to maximize compatibility and because enabling the IOMMU comes with a performance penalty due to the overhead of the address translations.”

A separate mitigation is to enable Error Correcting Codes (ECC) on the GPU, something Nvidia allows to be done using a command line. Like IOMMU, enabling ECC incurs some performance overhead because it reduces the overall amount of available workable memory. Further, some Rowhammer attacks can overcome ECC mitigations.

GPU users should understand that the only cards known to be vulnerable to Rowhammer are the RTX 3060 and RTX 6000 from the Ampere generation, which were introduced in 2020. It wouldn’t be surprising if newer generations of graphics cards from Nvidia and others are susceptible to the same types of attacks, but because the pace of academic research typically lags far behind the faster speed of product rollouts, there’s no way now to know.

Top-tier cloud platforms typically provide security levels that go well beyond those available by default on hobbyist and consumer machines. Another thing to remember: There are no known instances of Rowhammer attacks ever being actively used in the wild.

The true value of the research is to put GPU makers and users alike on notice that Rowhammer attacks on these platforms have the potential to upend security in serious ways. More information about GDDRHammer and GeForge is available here.



Source link

  • Related Posts

    A Year After DOGE Cuts, GSA Now Plans to Hire Hundreds of Employees

    A year after Elon Musk’s so-called Department of Government Efficiency (DOGE) effectively fired thousands of government employees, one federal agency that was affected by those cuts is now preparing to…

    Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web

    A publicly accessible Amazon-hosted storage server allowed anyone with a web browser to access potentially hundreds of thousands of people’s personal data without needing a password. This included driver’s licenses,…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Canada Gazette – Part I, June 21, 2025, volume 159, number 25

    B.C. experts weigh in whether the condo presale model is obsolete

    B.C. experts weigh in whether the condo presale model is obsolete

    Terry Glavin: The muddled and murky world of Michael Ma

    How Do You Count 1.4 Billion People? India Is Trying.

    A Year After DOGE Cuts, GSA Now Plans to Hire Hundreds of Employees

    A Year After DOGE Cuts, GSA Now Plans to Hire Hundreds of Employees

    Evangelicals backed Trump. Now pastors denounce his ICE crackdown hitting their churches.

    Evangelicals backed Trump. Now pastors denounce his ICE crackdown hitting their churches.