Database/Firmware, BMC & network fabric

EDK II NetworkPkg (DHCPv6 proxy Advertise, Server ID option): Buffer overflow in the proxy-DHCPv6 path
Impact
Buffer overflow in the proxy-DHCPv6 path - the exact path a PXE/HTTP-boot provisioning flow uses when the boot server and the address server are different boxes. Memory corruption in DXE means the attacker can potentially take the node before it has an OS, which for a multi-tenant bare-metal GPU fleet means a persistent foothold that outlives the tenant lease and the reimage.
Who can reach it
Unauthenticated, on-link attacker impersonating or racing the proxy DHCPv6 server on the provisioning segment. Pre-OS.
What to do
OEM BIOS update, flash and reboot each node. There is no OS-level patch and no runtime mitigation - the vulnerable code runs before the OS. Until the OEM ships, the practical controls are network-side: segment the provisioning VLAN away from tenant traffic, enforce DHCPv6 guard on access ports, and disable UEFI network boot on any node whose boot source is local NVMe.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc): Hardware flow-offload rules are programmed from a staleCVE-2023-54262 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc)High
- Intel Xeon memory controller configuration (with SGX): An improper conditions check in Xeon memory controllerCVE-2024-23918 · Intel Xeon memory controller configuration (with SGX)High
- Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008): TheCVE-2024-25744 · Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008)High
- AMI AptioV BIOS (improper input validation, SMM): A local attacker overwrites arbitrary memory and executes code at SMMCVE-2024-33659 · AMI AptioV BIOS (improper input validation, SMM)High
- Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10CVE-2024-48013 · Dell SmartFabric OS10 (execution with unnecessary privileges)High
- Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.xCVE-2024-49559 · Dell SmartFabric OS10 (default password)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.