Database/Firmware, BMC & network fabric
Intel BIOS firmware: Insufficient control-flow management in Intel BIOS firmware lets a privileged user escalate
Impact
Insufficient control-flow management in Intel BIOS firmware lets a privileged user escalate. Broad advisory covering many platform SKUs - check your specific board rather than assuming you are out of scope.
Who can reach it
Privileged local access on the host.
What to do
Fixed in platform BIOS/UEFI firmware. That means an OEM release, a per-node drain, a flash and a cold reboot - and OEM availability commonly lags the Intel advisory by quarters on server boards. There is no microcode or OS-level shortcut for this class; budget it as a fleet-wide maintenance campaign, not a patch.
References
Related entries
- Intel SGX SDK (asynchronous exit / exception handling): SmashEx: an asynchronous exception delivered at the rightCVE-2021-0186 · Intel SGX SDK (asynchronous exit / exception handling)Medium
- GRUB2 (short-form option parser): Heap out-of-bounds write in the short-form option parserCVE-2021-20225 · GRUB2 (short-form option parser)Medium
- GRUB2 (option quoting): Miscalculated buffer size when quoting options produces a heap out-of-bounds writeCVE-2021-20233 · GRUB2 (option quoting)Medium
- InsydeH2O: mishandled PlatformLangCodes UEFI variable overflows a buffer and exhausts firmware resourcesCVE-2021-43614 · Insyde InsydeH2O (PlatformLangCodes UEFI variable handling)Medium
- GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to startCVE-2022-28736 · GRUB2 (chainloader)Medium
- CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitraryCVE-2022-34301 · CryptoPro Secure Disk (signed UEFI bootloader)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.