{"id":2926,"date":"2026-05-06T11:04:03","date_gmt":"2026-05-06T11:04:03","guid":{"rendered":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/"},"modified":"2026-05-06T11:04:03","modified_gmt":"2026-05-06T11:04:03","slug":"rowhammer-attack-against-nvidia-chips","status":"publish","type":"post","link":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/","title":{"rendered":"Rowhammer Attack Against NVIDIA Chips"},"content":{"rendered":"<div>\n<p>A new <a href=\"https:\/\/en.wikipedia.org\/wiki\/Row_hammer\">rowhammer<\/a> attack gives <a href=\"https:\/\/arstechnica.com\/security\/2026\/04\/new-rowhammer-attacks-give-complete-control-of-machines-running-nvidia-gpus\/\">complete control<\/a> of NVIDIA CPUs.<\/p>\n<blockquote>\n<p>On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia\u2019s Ampere generation that take GPU rowhammering into new\u2014\u00adand potentially much more consequential\u2014\u00adterritory: GDDR bitflips that give adversaries full control of CPU memory, resulting in full system compromise of the host machine. For the attack to work, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Input-output_memory_management_unit\">IOMMU<\/a> memory management must be disabled, as is the default in BIOS settings.<\/p>\n<p>\u201cOur work shows that Rowhammer, which is well-studied on CPUs, is a serious threat on GPUs as well,\u201d said Andrew Kwong, co-author of one of the papers. \u201c<a href=\"https:\/\/gddr.fail\/files\/gddr.pdf\">GDDRHammer: Greatly Disturbing DRAM Rows\u00adCross-Component Rowhammer Attacks from Modern GPUs<\/a>.\u201d \u201cWith our work, we\u2026 show how an attacker can induce bit flips on the GPU to gain arbitrary read\/write access to all of the CPU\u2019s memory, resulting in complete compromise of the machine.\u201d<\/p>\n<p>Update Friday, April 3: On Friday, researchers unveiled a third Rowhammer attack that also demonstrates Rowhammer attacks on the RTX A6000 that achieves privilege escalation to a root shell. Unlike the previous two, the researchers said, it works even when IOMMU is enabled.<\/p>\n<\/blockquote>\n<p>The second paper is <a href=\"https:\/\/gddr.fail\/files\/GeForge.pdf\">GeForge: Hammering GDDR Memory to Forge GPU Page Tables for Fun and Profit<\/a>:<\/p>\n<blockquote>\n<p>\u2026does largely the same thing, except that instead of exploiting the last-level page table, as GDDRHammer does, it manipulates the last-level page directory. It was able to induce 1,171 bitflips against the RTX 3060 and 202 bitflips against the RTX 6000.<\/p>\n<p>GeForge, too, uses novel hammering patterns and memory massaging to corrupt GPU page table mappings in GDDR6 memory to acquire read and write access to the GPU memory space. From there, it acquires the same privileges over host CPU memory. The GeForge proof-of-concept exploit against the RTX 3060 concludes by opening a root shell window that allows the attacker to issue commands that run unfettered privileges on the host machine. The researchers said that both GDDRHammer and GeForge could do the same thing against the RTC 6000.<\/p>\n<\/blockquote>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new rowhammer attack gives complete control of NVIDIA CPUs. On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia\u2019s Ampere generation that take GPU rowhammering into new\u2014\u00adand potentially much more consequential\u2014\u00adterritory: GDDR bitflips that give adversaries full control of CPU memory, resulting in full system compromise of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[330,299,90,274,940,53],"tags":[91],"class_list":["post-2926","post","type-post","status-publish","format-standard","hentry","category-academic-papers","category-cyberattack","category-cybersecurity","category-hacking","category-hardware","category-uncategorized","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Rowhammer Attack Against NVIDIA Chips - Imperative Business Ventures Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Rowhammer Attack Against NVIDIA Chips - Imperative Business Ventures Limited\" \/>\n<meta property=\"og:description\" content=\"A new rowhammer attack gives complete control of NVIDIA CPUs. On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia\u2019s Ampere generation that take GPU rowhammering into new\u2014\u00adand potentially much more consequential\u2014\u00adterritory: GDDR bitflips that give adversaries full control of CPU memory, resulting in full system compromise of [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/\" \/>\n<meta property=\"og:site_name\" content=\"Imperative Business Ventures Limited\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-06T11:04:03+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"headline\":\"Rowhammer Attack Against NVIDIA Chips\",\"datePublished\":\"2026-05-06T11:04:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/\"},\"wordCount\":338,\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"academic papers\",\"cyberattack\",\"Cybersecurity\",\"hacking\",\"hardware\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/\",\"url\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/\",\"name\":\"Rowhammer Attack Against NVIDIA Chips - Imperative Business Ventures Limited\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/#website\"},\"datePublished\":\"2026-05-06T11:04:03+00:00\",\"author\":{\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.ibvl.in\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Rowhammer Attack Against NVIDIA Chips\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.ibvl.in\/#website\",\"url\":\"https:\/\/blog.ibvl.in\/\",\"name\":\"Imperative Business Ventures Limited\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.ibvl.in\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/blog.ibvl.in\"],\"url\":\"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Rowhammer Attack Against NVIDIA Chips - Imperative Business Ventures Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/","og_locale":"en_US","og_type":"article","og_title":"Rowhammer Attack Against NVIDIA Chips - Imperative Business Ventures Limited","og_description":"A new rowhammer attack gives complete control of NVIDIA CPUs. On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia\u2019s Ampere generation that take GPU rowhammering into new\u2014\u00adand potentially much more consequential\u2014\u00adterritory: GDDR bitflips that give adversaries full control of CPU memory, resulting in full system compromise of [&hellip;]","og_url":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/","og_site_name":"Imperative Business Ventures Limited","article_published_time":"2026-05-06T11:04:03+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/#article","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/"},"author":{"name":"admin","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"headline":"Rowhammer Attack Against NVIDIA Chips","datePublished":"2026-05-06T11:04:03+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/"},"wordCount":338,"keywords":["Cybersecurity"],"articleSection":["academic papers","cyberattack","Cybersecurity","hacking","hardware"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/","url":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/","name":"Rowhammer Attack Against NVIDIA Chips - Imperative Business Ventures Limited","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/#website"},"datePublished":"2026-05-06T11:04:03+00:00","author":{"@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"breadcrumb":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/05\/06\/rowhammer-attack-against-nvidia-chips\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.ibvl.in\/"},{"@type":"ListItem","position":2,"name":"Rowhammer Attack Against NVIDIA Chips"}]},{"@type":"WebSite","@id":"https:\/\/blog.ibvl.in\/#website","url":"https:\/\/blog.ibvl.in\/","name":"Imperative Business Ventures Limited","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.ibvl.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/blog.ibvl.in"],"url":"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/comments?post=2926"}],"version-history":[{"count":0,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2926\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/media?parent=2926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/categories?post=2926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/tags?post=2926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}