Database/Firmware, BMC & network fabric

OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer found
Impact
The second bug the fuzzer found while the first one was being patched - same parser, same unauthenticated reachability, same result of taking down Redfish, KVM and SoL together. Its real value to an operator is as evidence about the code: bmcweb's multipart handling was not hardened, it was patched twice under fuzzing pressure, and the 2026 disclosures below show the same pattern repeating in the HTTP/2 and Expect-header paths. Treat bmcweb version currency as a standing fleet metric rather than a per-CVE chase.
Who can reach it
Unauthenticated HTTP(S) request to bmcweb on the management interface. No credentials, no host access.
What to do
Same patch train as CVE-2022-2809 - bmcweb 2.13 and later, arriving as a BMC firmware flash per node, out-of-band, ODM-lagged. There is no separate action for this one. The operator-level control that actually pays: know the bmcweb version on every node in your fleet and put a floor on it in your acceptance criteria for ODM firmware drops.
References
Related entries
- Dell Enterprise SONiC OS (SSH cryptographic key): A cryptographic key weakness in SONiC's SSH implementation letsCVE-2022-34425 · Dell Enterprise SONiC OS (SSH cryptographic key)High
- Intel OpenBMC firmware (before version 0.72) - network-facing service: An unauthenticated caller reads out of boundsCVE-2022-35729 · Intel OpenBMC firmware (before version 0.72) - network-facing serviceHigh
- AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMCCVE-2022-40242 · AMI MegaRACHigh
- Linux kernel (drivers/infiniband/hw/irdma): A permanent kernel hang once any queue-pair goes to error.CVE-2022-48694 · Linux kernel (drivers/infiniband/hw/irdma)High
- Linux kernel (drivers/infiniband/sw/siw): A remote peer crashes the node during connection setup. When the MPACVE-2022-50136 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/rxe): A null-pointer dereference panics the node whenever queue-pair creation failsCVE-2022-50885 · Linux kernel (drivers/infiniband/sw/rxe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.