GPUBreach Attack: GPU Rowhammer Leads to Full System Compromise

GPUBreach Attack: GPU Rowhammer Leads to Full System Compromise

Researchers have unveiled a novel attack dubbed GPUBreach, capable of leveraging Rowhammer bit-flips on GPU GDDR6 memory to achieve privilege escalation and ultimately, complete system takeover. This isn’t just about corrupting data; GPUBreach targets GPU page tables (PTEs) to grant an unprivileged CUDA kernel arbitrary read/write access to GPU memory. According to the researchers, this capability can then be chained with exploits for memory-safety bugs found in NVIDIA drivers, potentially leading to a root shell on the CPU.

What’s particularly concerning is that GPUBreach can bypass Input-Output Memory Management Unit (IOMMU) protections, a hardware safeguard typically effective against direct memory access (DMA) attacks. The University of Toronto team, who developed the exploit, will present their findings at the IEEE Symposium on Security & Privacy. They emphasize that GPUBreach represents a significant advancement, moving GPU Rowhammer attacks from mere data corruption to potent privilege escalation, even when IOMMU is active.

What This Means For You

  • Security teams should prioritize patching NVIDIA drivers and closely monitor for unusual GPU memory access patterns, as GPUBreach demonstrates a viable attack path bypassing traditional DMA protections.
πŸ”Ž
Is your vendor affected? Start hunting now. Search by organization or domain, set watchlist alerts, and get notified when your third parties are compromised.
Open Intel Bot β†’

Related coverage

Trend Micro Apex One Zero-Day Under Active Exploitation

Trend Micro has confirmed a zero-day vulnerability in its Apex One security product, actively exploited on Windows systems. BleepingComputer reports that this critical flaw allows...

threat-inteldata-breachmalwarevulnerabilitymicrosoft
/SCW Vulnerability Desk /HIGH /⚑ 2 IOCs /⚙ 3 Sigma

Ubiquiti Patches Three Max Severity UniFi OS Vulnerabilities

Ubiquiti has rolled out critical security updates addressing three maximum severity vulnerabilities in UniFi OS. BleepingComputer reports these flaws, tracked as CVE-2023-48092, CVE-2023-48093, and CVE-2023-48094,...

threat-inteldata-breachmalwarevulnerabilitytools
/SCW Vulnerability Desk /MEDIUM /⚑ 3 IOCs /⚙ 1 Sigma

Tech Giants Commit to UK Child Safety Tweaks for Ofcom

Major tech companies, including Roblox, Snapchat, Instagram, Facebook, YouTube, and TikTok, have pledged to implement platform adjustments aimed at enhancing child protection online. This commitment...

threat-inteldata-breachgovernment
/SCW Research /MEDIUM