Database/Firmware, BMC & network fabric

EDK II NetworkPkg (DHCPv6 DNS Servers option handling): A crafted DNS Servers option inside a DHCPv6 Advertise
Impact
A crafted DNS Servers option inside a DHCPv6 Advertise overflows a firmware buffer, giving memory corruption and a plausible route to pre-boot code execution. Same class of loss as the Server ID overflow: an attacker who lands here is executing inside DXE, above the OS and outside anything the tenant's EDR or attestation agent can see.
Who can reach it
Unauthenticated attacker able to answer DHCPv6 on the provisioning network during the node's PXE boot. No physical access, no host credentials.
What to do
Firmware flash from the server OEM, not from Tianocore - the upstream edk2 patch has to be rebased by your IBV and then re-qualified by the OEM, which historically takes one to two BIOS release cycles. One reboot per node. Immediate config workaround: disable IPv6 in the UEFI network boot stack, or disable network boot on nodes that do not need it, and restrict who can emit DHCPv6/RA on the deployment VLAN.
References
Related entries
- EDK II NetworkPkg (DHCPv6 proxy Advertise, Server ID option): Buffer overflow in the proxy-DHCPv6 pathCVE-2023-45235 · EDK II NetworkPkg (DHCPv6 proxy Advertise, Server ID option)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc): Hardware flow-offload rules are programmed from a staleCVE-2023-54262 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc)High
- Intel Xeon memory controller configuration (with SGX): An improper conditions check in Xeon memory controllerCVE-2024-23918 · Intel Xeon memory controller configuration (with SGX)High
- Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008): TheCVE-2024-25744 · Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008)High
- AMI AptioV BIOS (improper input validation, SMM): A local attacker overwrites arbitrary memory and executes code at SMMCVE-2024-33659 · AMI AptioV BIOS (improper input validation, SMM)High
- Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10CVE-2024-48013 · Dell SmartFabric OS10 (execution with unnecessary privileges)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.