Database/Firmware, BMC & network fabric

Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flash: The OS
Impact
The OS or hypervisor can reach the SPI-NOR boot flash through an insufficiently protected SMC. That means whoever owns the kernel on an Altra box can rewrite platform firmware - a persistent, below-the-OS implant that survives reimaging, disk wipe and tenant handoff. For a bare-metal Arm GPU provider this is the canonical tenant-persistence failure: rent a node for an hour, own it for its service life. It also destroys any attestation story you have told customers.
Who can reach it
Any code at host kernel or hypervisor level on an Altra / Altra Max system - which, on bare-metal rental, means the tenant by design. No physical access needed.
What to do
Update to Altra SRP 1.09 or later from the board OEM (the fix hardens the SMC so the non-secure world can no longer drive SPI-NOR). Flash + reboot + drain per node, and the OEM has to ship an SRP build for your specific board - Ampere publishes the reference, your ODM integrates it, so the lag is on them. Independently and more importantly: on bare-metal, verify boot flash contents against a golden image at every tenant handoff. Assume any node rented before the SRP update may already carry an implant and reflash it from an out-of-band path rather than trusting in-band verification.
References
Related entries
- APC Easy UPS Online Monitoring Software (Windows and Windows Server): Critical functions in the UPS monitoring serverCVE-2022-42970 · APC Easy UPS Online Monitoring Software (Windows and Windows Server)Critical
- APC Easy UPS Online Monitoring Software (Windows and Windows Server): Unrestricted file upload leads to remote codeCVE-2022-42971 · APC Easy UPS Online Monitoring Software (Windows and Windows Server)Critical
- Ampere Altra and Altra Max before firmware 2.10c - PCIe root complex access control: The OS can re-initialise a PCIeCVE-2022-46892 · Ampere Altra and Altra Max before firmware 2.10c - PCIe root complex access controlCritical
- Linux SUNRPC / NFS-over-RDMA server (svc_rdma_build_writes): svc_rdma_build_writes can walk off the end of a WriteCVE-2022-49356 · Linux SUNRPC / NFS-over-RDMA server (svc_rdma_build_writes)Critical
- Linux kernel (drivers/infiniband/sw/siw): A remote peer turns a connection drop into a kernel use-after-free. TheCVE-2022-50666 · Linux kernel (drivers/infiniband/sw/siw)Critical
- SAUTER Controls Nova 200-220 series (firmware <=3.3-006) with BACnetstac <=4.2.1: Commands execute with no credentialsCVE-2023-0052 · SAUTER Controls Nova 200-220 series (firmware <=3.3-006) with BACnetstac <=4.2.1Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.