Database/Firmware, BMC & network fabric
Arm Trusted Firmware-A through v2.8, X.509 certificate parser used by Trusted Board Boot (get_ext, auth_nvctr)
Impact
The code that validates the secure boot certificate chain reads out of bounds on a malformed certificate. So the component whose entire job is to decide whether firmware is trustworthy can be driven off the rails by the untrusted input it is inspecting - dangerous read side effects and leakage of microarchitectural state. It undermines the chain of trust at the exact point where a bare-metal operator is trying to prove to the next tenant that the box is clean.
Who can reach it
An attacker able to place a crafted certificate in the boot chain: control of the firmware image or the firmware-update path. On bare-metal GPU rental, a prior tenant with flash write access. Not remote.
What to do
Upgrade TF-A past v2.8 with the TFV-10 fix and have the OEM re-issue the platform firmware. Flash + reboot + drain per node. There is no runtime mitigation - the parser runs before anything you control. Pair it with the operational control that actually helps: measure and attest boot firmware between tenants instead of trusting the parser.
References
Related entries
- AMD SMM module: heap overflow yields SMM code execution when chained with an SPI flash write flawCVE-2023-20577 · AMD platform firmware SMM module (EPYC server and Instinct MI300A BIOS)High
- shim (verify_sbat_section): Integer overflow leading to heap overflow while verifying the SBAT section on 32-bitCVE-2023-40548 · shim (verify_sbat_section)High
- Dell OMSA: unauthenticated SSRF turns the management agent into a proxy into the management VLANCVE-2026-81446 · Dell OpenManage Server Administrator (SSRF, unauthenticated)High
- Intel SGX (L1 terminal fault on enclave pages): Speculative execution lets code outside an enclave read the enclave'sCVE-2018-3615 · Intel SGX (L1 terminal fault on enclave pages)High
- AMD Secure Processor Secure OS - memory buffer checking: A malicious trusted application can read and write the ASPCVE-2022-23817 · AMD Secure Processor Secure OS - memory buffer checkingHigh
- Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against ActiveCVE-2023-29057 · Lenovo XClarity Controller (XCC) - LDAP/AD authorizationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.