CISOOnline

GPUThor hardware attack can root Nvidia GPU systems

However, the researchers also tested Nvidia server GPUs such as A100 and H100 or newer GPUs on the Blackwell architecture like RTX 5090 or RTX 6000, and their attack did not produce bit flips. This is because these cards use different or newer type of memory such as HBM, GDDR6X, and GDDR7, which have different defenses. The research team plans to investigate these chips in the future so they don’t discount the possibility that alternative attack patterns could exist for them.

Why does this matter?

In the age of AI models, enterprise and server-class GPUs are valuable because they are needed for both training or fine-tuning AI models and for running them, known as inference. Even without AI, these GPUs are usually installed in datacenters and run sensitive workloads often from multiple virtual machines at the same time.

In their tests, the researchers managed to crash GPUs so often that within one day the cards flagged themselves as defective and due for replacement using their internal crash detection mechanisms. Aside from triggering denial-of-service conditions that kill all the workloads running on the card, the researchers managed to corrupt the GPU’s memory page tables in a way that allowed an unprivileged program to escalate its privileges to root.



Source link