Database/Firmware, BMC & network fabric

EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling): A truncated ND Redirect message drives an out-of-bounds
Impact
A truncated ND Redirect message drives an out-of-bounds read in the firmware IPv6 stack. Practical outcome is firmware memory disclosure or a wedged boot; the more interesting operational consequence is that the Redirect path itself lets an on-link attacker steer where the booting node sends its traffic, so this is both a leak and a foothold for redirecting the netboot fetch.
Who can reach it
On-link IPv6 attacker on the provisioning segment - any host that can emit ICMPv6 Neighbor Discovery to the booting node. Unauthenticated, pre-OS.
What to do
OEM BIOS update, flash + reboot per node; the IBV-to-OEM rebase lag applies. Interim: enable IPv6 RA Guard / ND inspection on the provisioning switches, and disable the UEFI IPv6 network stack on nodes that boot locally. No OS-level or config-in-firmware toggle short of turning network boot off.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/ipoib): The IPoIB multicast join task drops its lock mid-iteration, letting aCVE-2023-52587 · Linux kernel (drivers/infiniband/ulp/ipoib)Medium
- Linux kernel (drivers/infiniband/core): Rdma_join_multicast accepted queue-pair types other than UD and built theCVE-2023-53525 · Linux kernel (drivers/infiniband/core)Medium
- Arista EOS (L2 forwarding / VLAN isolation): Ingress traffic on a layer-2 port is forwarded out ports belonging to aCVE-2024-11185 · Arista EOS (L2 forwarding / VLAN isolation)Medium
- Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series servers: An administrator-levelCVE-2024-20365 · Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series serversMedium
- Intel Ethernet Controller E810 firmware: An unauthenticated attacker on the network can take an E810 NIC out of serviceCVE-2024-24983 · Intel Ethernet Controller E810 firmwareMedium
- SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injection: An untrusted hypervisor can inject the #VCCVE-2024-25742 · SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injectionMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.