Database/Firmware, BMC & network fabric

EDK2: BIOS exposes sensitive information to a local unauthorized actor
Impact
A local user on the machine can read data the firmware should keep to itself, and the advisory states the outcome may extend to privilege escalation. EDK2 is the upstream most server BIOS images are built from, so the exposure follows whatever your platform vendor shipped rather than one product. On a GPU node the concern is firmware-held material - keys, measurements, configuration - that underpins secure boot and attestation: if it leaks, the attestation a tenant relies on no longer proves what it claims. The record gives high attack complexity and requires local low-privileged access, so this is a slow escalation path, not a remote break-in. The description is thin on the specific code path; treat the mechanism as unestablished.
Who can reach it
Local user on the host with low privileges. No remote or network path, and no tenant-facing path unless a workload already has host-level code execution.
What to do
There is no EDK2 fix you deploy directly - wait for the BIOS release from your server vendor that picks up the EDK2 fix, then flash each affected node. That means scheduling the node out of service: drain workloads, flash, reboot, re-attest. Plan it as part of a routine firmware campaign rather than an emergency window, given the local-only, high-complexity attack path. The record names no fixed EDK2 tag.
References
Related entries
- Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedCVE-2024-6437 · Arista EOS (PBR / BGP Flowspec / interface traffic policy)Medium
- AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeCVE-2025-33043 · AMI AptioV UEFI BIOSMedium
- Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andCVE-2026-7473 · Arista EOS (tunnel decapsulation)Medium
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapCVE-2020-15707 · GRUB2 (initrd size handling)Medium
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathCVE-2021-3696 · GRUB2 (PNG grayscale reader)Medium
- AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, soCVE-2023-34472 · AMI MegaRAC SPx (BMC web interface, HTTP header handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.