Database/Firmware, BMC & network fabric

ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed): The driver brings the video engine
Impact
The driver brings the video engine out of reset in the wrong order relative to its two clocks, and the hardware responds by issuing DMA writes to effectively random BMC memory. This is a DMA engine scribbling on the management processor's RAM with no software mediating the target address - the failure mode is silent BMC state corruption and unexplained BMC hangs or reboots. Operators usually log these as flaky hardware and RMA the board; the actual cost is a management processor whose memory integrity you cannot reason about, on every node running an affected image with video capture enabled.
Who can reach it
Triggers on video engine initialization, i.e. whenever iKVM/video capture is started or restarted on an affected BMC image. No attacker required for the corruption itself, but a host-side tenant who can force display-mode changes can force the reinit repeatedly.
What to do
Fixed in the kernel driver and backported to stable branches; delivery is a BMC firmware flash, per node, out-of-band, ODM-gated. Config-only mitigation is to leave the video capture service stopped on nodes that do not use graphical console. Worth pairing with a check of your BMC crash/reboot telemetry - if you have unexplained BMC resets on ASPEED nodes with iKVM enabled, this is a candidate cause rather than bad silicon.
References
Related entries
- Intel RDMA driver for Ethernet X722 and 800 series (Linux): Improper input validation in the Intel RDMA Linux driverCVE-2021-0084 · Intel RDMA driver for Ethernet X722 and 800 series (Linux)High
- BMC firmware on the HPE Cloudline whitebox line: An attacker directs the BMC's video-deletion routine at arbitraryCVE-2021-25124 · BMC firmware on the HPE Cloudline whitebox lineHigh
- AMD PSP boot ROM - integrity of decrypted firmware image: The PSP boot ROM authenticates and decrypts firmware but doesCVE-2021-26315 · AMD PSP boot ROM - integrity of decrypted firmware imageHigh
- AMD SEV-ES Trusted Memory Region - SNP guest memory integrity: A bug in the SEV-ES Trusted Memory Region handling costsCVE-2021-26324 · AMD SEV-ES Trusted Memory Region - SNP guest memory integrityHigh
- AMD Secure Processor (ASP) bootloader - image header parsing: The ASP bootloader reads and acts on fields from aCVE-2021-26335 · AMD Secure Processor (ASP) bootloader - image header parsingHigh
- AMD Secure Processor - SoC security-configuration registers: A local attacker can make unauthorised changes to theCVE-2021-26360 · AMD Secure Processor - SoC security-configuration registersHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.