Database/Firmware, BMC & network fabric

EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing): Same shape as the unknown-option hang but
Impact
Same shape as the unknown-option hang but reached through the PadN option, which is trivially craftable. One packet parks a node in firmware forever. In a netboot-driven cluster this is a cheap way to deny an operator their fleet during a reprovisioning window, and the failure looks like a hardware fault rather than an attack.
Who can reach it
Unauthenticated, on-link attacker sending crafted IPv6 packets to nodes during network boot.
What to do
Firmware flash from the server OEM, one reboot per node. No runtime fix. Practical interim control is to disable IPv6 network boot in the UEFI setup (a config change, deployable via the OEM's remote BIOS-settings tooling without a flash) and to keep the provisioning VLAN reachable only from the deployment controllers.
References
Related entries
- EDK II NetworkPkg (TCP initial sequence number generation): The firmware's TCP initial sequence numbersCVE-2023-45236 · EDK II NetworkPkg (TCP initial sequence number generation)High
- EDK II NetworkPkg (PseudoRandom number generation used by the network stack): The weak PRNG behind the previous issueCVE-2023-45237 · EDK II NetworkPkg (PseudoRandom number generation used by the network stack)High
- Lenovo XClarity Controller (XCC) - permission API: An authenticated XCC user can change the permissions of any userCVE-2023-4607 · Lenovo XClarity Controller (XCC) - permission APIHigh
- HPE iLO 5 / iLO 6 (authentication bypass): Authentication bypass on the iLO itself, remotely, with no credentialsCVE-2023-50272 · HPE iLO 5 / iLO 6 (authentication bypass)High
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestCVE-2023-52513 · Linux kernel (drivers/infiniband/sw/siw)High
- Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM): A buffer overflow in howCVE-2024-0762 · Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.