NVIDIA DGX A100 - SBIOS / SMM firmware: The BiosCfgTool reads and writes outside its bounds in SMRAM, handing
Impact
The BiosCfgTool reads and writes outside its bounds in SMRAM, handing a privileged local user code execution in System Management Mode with a changed scope. This is firmware-level persistence: it survives OS reinstall, image re-flash and tenant handoff, and it is invisible to anything running above it. On a bare-metal GPU rental business it is the difference between wiping a node between tenants and not actually being able to.
Who can reach it
Local and already privileged - host root, or code that has reached the platform firmware/SMM path. It is not a first foothold; it is what turns a one-time root compromise into something you cannot remediate by reimaging.
What to do
Flash the fixed SBIOS from bulletin 5367. Cost: not live-patchable. Full node drain, host power cycle, and on DGX the SBIOS ships inside a firmware bundle alongside BMC and CPLD components, so budget 30-60 minutes of node downtime plus a post-flash health check. Firmware rollback protection means you cannot cleanly revert - stage on one node before the fleet.
References
Related entries
- NVIDIA DGX A100 - SBIOS / SMM firmware: An uninitialised pointer in the Ofbd SMM handler gives a privileged local userCVE-2022-31599 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX A100 - SBIOS / SMM firmware: An integer overflow in SmmCore, chainable from another bug, reaches SMM codeCVE-2022-31600 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX A100 - SBIOS / SMM firmware: The SmiFlash SMM handler lets a privileged local user read, write and eraseCVE-2022-42276 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX A100 - SBIOS / SMM firmware: The GenericSio and LegacySmmSredir SMM APIs allow arbitrary modificationCVE-2023-0202 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX A100 - SBIOS / SMM firmware: The NVME SMM API allows arbitrary SMRAM modification, again reaching full SMMCVE-2023-0206 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX A100 - SBIOS / SMM firmware: An out-of-bounds write in the SmbiosPei module gives a highly privileged localCVE-2022-31601 · NVIDIA DGX A100 - SBIOS / SMM firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.