Database/Firmware, BMC & network fabric

EDK II NetworkPkg (DHCPv6 Advertise, IA_NA/IA_TA option parsing): An integer underflow when parsing
Impact
An integer underflow when parsing the identity-association options in a DHCPv6 Advertise causes the firmware to read outside its buffer. On its own this leaks firmware memory contents or crashes the boot; chained with the overflow bugs in the same advertisement path it is the information-leak half of a reliable pre-OS exploit (defeating whatever address-layout guesswork the attacker would otherwise need).
Who can reach it
Anyone able to send DHCPv6 Advertise messages on the segment the node PXE-boots from. Unauthenticated, pre-OS.
What to do
Firmware flash via the server OEM's BIOS package - the fix is in upstream edk2 but only reaches you after the IBV rebase and the OEM's own validation cycle. Reboot per node. Config-only stopgap: disable IPv6 network boot, or PXE entirely, and treat the provisioning VLAN as a trust boundary that tenant workloads must never reach.
References
Related entries
- EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling): A truncated ND Redirect message drives an out-of-boundsCVE-2023-45231 · EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling)Medium
- Linux kernel (drivers/infiniband/ulp/ipoib): The IPoIB multicast join task drops its lock mid-iteration, letting aCVE-2023-52587 · Linux kernel (drivers/infiniband/ulp/ipoib)Medium
- Linux kernel (drivers/infiniband/core): Rdma_join_multicast accepted queue-pair types other than UD and built theCVE-2023-53525 · Linux kernel (drivers/infiniband/core)Medium
- Arista EOS (L2 forwarding / VLAN isolation): Ingress traffic on a layer-2 port is forwarded out ports belonging to aCVE-2024-11185 · Arista EOS (L2 forwarding / VLAN isolation)Medium
- Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series servers: An administrator-levelCVE-2024-20365 · Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series serversMedium
- Intel Ethernet Controller E810 firmware: An unauthenticated attacker on the network can take an E810 NIC out of serviceCVE-2024-24983 · Intel Ethernet Controller E810 firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.