Database/Firmware, BMC & network fabric
Intel Ethernet 700 Series Controller firmware (access control): Insufficient access control inside 700-series NIC
Impact
Insufficient access control inside 700-series NIC firmware lets a privileged host user escalate further or deny service. On bare-metal GPU rental the 'privileged host user' is the tenant, and the thing they are escalating into is firmware that the next tenant will inherit. This is the concrete mechanism behind the tenant-handoff problem: patching the host OS between customers does nothing about the NIC.
Who can reach it
A privileged local user on the host — in a bare-metal rental model, the customer with root.
What to do
Flash 700-series firmware to 7.3 or later; cold power cycle. Operationally the stronger control is to reflash NIC firmware from a known-good image at every tenant handoff and verify the resulting version, rather than trusting whatever the previous tenant left behind. Related issues fixed in the same family: CVE-2020-8691, CVE-2020-8693, CVE-2019-0139, CVE-2019-0144.
References
Related entries
- Intel BIOS firmware: Insufficient control-flow management in Intel BIOS firmware lets a privileged user escalateCVE-2021-0157 · Intel BIOS firmwareMedium
- Intel SGX SDK (asynchronous exit / exception handling): SmashEx: an asynchronous exception delivered at the rightCVE-2021-0186 · Intel SGX SDK (asynchronous exit / exception handling)Medium
- GRUB2 (short-form option parser): Heap out-of-bounds write in the short-form option parserCVE-2021-20225 · GRUB2 (short-form option parser)Medium
- GRUB2 (option quoting): Miscalculated buffer size when quoting options produces a heap out-of-bounds writeCVE-2021-20233 · GRUB2 (option quoting)Medium
- InsydeH2O: mishandled PlatformLangCodes UEFI variable overflows a buffer and exhausts firmware resourcesCVE-2021-43614 · Insyde InsydeH2O (PlatformLangCodes UEFI variable handling)Medium
- GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to startCVE-2022-28736 · GRUB2 (chainloader)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.