Database/Firmware, BMC & network fabric
Arm Trusted Firmware-M: Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPE
CVSS 5.5CVE-2021-27562Firmware, BMC & network fabriccurated
Impact
Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPE handler — relevant to BMC SoCs and DPUs built on Arm TrustZone
Who can reach it
Local
What to do
Firmware update of the affected Arm-based management controller; on a BMC this is again an ODM-gated rebase
References
Related entries
- Intel SGX Linux kernel driver: Uncontrolled resource consumption in the in-kernel SGX driver lets a local authenticatedCVE-2021-33135 · Intel SGX Linux kernel driverMedium
- Linux kernel RDMA core (UVERBS_METHOD_QUERY_GID_TABLE): The GID-table query handler used a user-supplied entry sizeCVE-2021-47080 · Linux kernel RDMA core (UVERBS_METHOD_QUERY_GID_TABLE)Medium
- Linux KVM SEV API - host kernel crash from unprivileged guest creation: A non-root host user-level application canCVE-2022-0171 · Linux KVM SEV API - host kernel crash from unprivileged guest creationMedium
- Intel processors (shared buffers data sampling): Incomplete cleanup of microarchitectural fill buffers lets a localCVE-2022-21125 · Intel processors (shared buffers data sampling)Medium
- Intel processors (post-barrier return stack buffer): PBRSB: return predictions made after an IBPB barrier can still useCVE-2022-26373 · Intel processors (post-barrier return stack buffer)Medium
- Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write accessCVE-2022-43309 · Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.