Database/Firmware, BMC & network fabric

AMI AptioV BIOS (memory buffer restriction failure): Local privilege escalation and potentially arbitrary code
CVE-2024-33658Firmware, BMC & network fabriccurated
Impact
Local privilege escalation and potentially arbitrary code execution in firmware.
Who can reach it
Local low-privilege access.
What to do
AMI ships the fix to OEMs, not to you - obtain the updated BIOS from your board/server vendor (Supermicro, Gigabyte, ASRock Rack, Quanta, Tyan etc.) and flash it. Expect a lag of weeks to months between the AMI advisory and an OEM image for your exact SKU, and expect some SKUs never to get one. Cold reboot per node.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.