Database/Firmware, BMC & network fabric

ASPEED video engine capture driver (drivers/media/platform/aspeed) - iKVM path: The video engine writes past
Impact
The video engine writes past its capture buffer when the host is driving a 1600x900 mode, corrupting whatever BMC kernel memory sits after it. The reported repro is mundane: run iKVM with virtual media mounted while the BMC is under memory pressure. Since the resolution is chosen by the host, a tenant with control of the server's display output can steer the BMC into the corrupting mode on demand. Realistically this is a BMC crash - which on a GPU node means losing remote power control and console right when you need it - but out-of-bounds writes driven by attacker-chosen geometry are the raw material for something worse.
Who can reach it
The host side picks the video mode, so any tenant with root on the bare-metal node can select it. Triggering the corruption additionally needs the BMC's iKVM/video capture to be running, which is the normal state on fleets that leave remote console available.
What to do
Kernel fix backported into stable; reaching your fleet means a BMC firmware flash per node, out-of-band, waiting on the ODM rebase. Config-only stopgap: disable the iKVM/video capture service on nodes that do not need graphical remote console. On a GPU fleet that is usually acceptable - operators run serial-over-LAN and Redfish, not KVM - and it removes both this bug and the video-engine DMA issue below without touching firmware.
References
Related entries
- Linux kernel (drivers/infiniband/core): A 32-bit advance counter in the core RDMA block iterator wraps when a singleCVE-2023-53026 · Linux kernel (drivers/infiniband/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A userspace DEVX consumer can issue a firmware command opcodeCVE-2023-53340 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a regular receive queue is reactivated after an AF_XDPCVE-2023-53394 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/infiniband/hw/bnxt_re): The driver keeps scheduling completion handlers for a queue pair afterCVE-2023-54048 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Linux kernel mlx4_ib (legacy ConnectX-3 RDMA): Same class of bug on the older mlx4 stack: the user-suppliedCVE-2023-54168 · Linux kernel mlx4_ib (legacy ConnectX-3 RDMA)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Adding a TC flower rule while the device is in NIC mode makesCVE-2023-54216 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.