Nvidia's Rowhammer Fix Bypassed by New Attack Technique
A team of researchers from the University of Toronto has developed a new attack technique called GPUThor that can bypass Nvidia's Rowhammer fix on certain graphics processing units (GPUs). The attack, which was published in a paper on August 25, uses a non-uniform hammering pattern to evade the chip's built-in defence mechanism. This allows an attacker to flip bits in a victim's data or crash the shared GPU.
The researchers tested their technique on four Ampere-generation workstation cards: the RTX A4000, A4500, A5000, and A6000. They found that with error correction enabled, GPUThor can force a GPU reset every two hours, killing every job on the card. Within a day, the GPU declares itself defective and asks to be replaced.
The researchers also demonstrated three things an attacker can do using GPUThor: denial of service, takeover, and silent corruption. They found that privilege escalation can still work on A100 server GPUs, which use the same class of error correction as the affected workstation parts.