New Rowhammer attacks give complete control of machines running Nvidia GPUs

arstechnica.com

132 points by 01-_- 3 days ago


stratos123 - 3 days ago

Notable parts:

- "GPU users should understand that the only cards known to be vulnerable to Rowhammer are the RTX 3060 and RTX 6000 from the Ampere generation"

- mitigations are enabling ECC on the GPU or enabling IOMMU in BIOS

So doesn't sound like a big deal for users, this is more of a datacenter sort of vulnerability. The fact that this attack is possible at all (you can turn small GPU memory writes into access to CPU memory) is pretty shocking to me, though.

aidenn0 - 2 days ago

Given that attacks tend to improve, how likely is it we can see this used to e.g. make a webgl attack that can compromise a machine?

okspAQ - 2 days ago

[dead]