Database/Control plane, storage & DevOps

DMTF libspdm - SPDM Requester timeout handling: A libspdm Requester stores the Responder's CTExponent
Impact
A libspdm Requester stores the Responder's CTExponent without validating it, so a malicious or faulty responder can force an enormous computed timeout and hang the requester. In an attestation flow this is a denial of service against the thing that decides whether a device is trustworthy - and a hung attestation is often failed open by the surrounding orchestration.
Who can reach it
Adjacent, unauthenticated with user interaction. A device on the link that answers CAPABILITIES dishonestly.
What to do
Update to libspdm 2.3.3 / 3.0 or later, again through your device vendor's firmware. Separately, check what your orchestration does when attestation times out rather than fails - failing open on timeout is the more damaging half of this.
References
Related entries
- Dell OpenManage Enterprise (path traversal): An unauthenticated remote attacker reads files from the OME serverCVE-2024-25944 · Dell OpenManage Enterprise (path traversal)Medium
- Elastic Metricbeat: oversized Prometheus remote_write request drives an unbounded allocation and kills the beatCVE-2026-26931 · Elastic Metricbeat (Prometheus remote_write HTTP handler)Medium
- AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT): AMD's split scheduler design gives eachCVE-2021-46778 · AMD Zen 1 / Zen 2 / Zen 3 - execution unit scheduler queue contention (SMT)Medium
- IBM Spectrum Scale / GPFS node file access path: An unprivileged but authenticated user on a GPFS node reads arbitraryCVE-2018-1723 · IBM Spectrum Scale / GPFS node file access pathMedium
- IBM GPFS command line utility: Any unprivileged user with a shell on a GPFS node can force GPFS down on that nodeCVE-2018-1783 · IBM GPFS command line utilityMedium
- Slurm (slurmdbd.conf file permissions): slurmdbd.conf is installed world-readable, which leaks the accountingCVE-2019-19727 · Slurm (slurmdbd.conf file permissions)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.