Database/Firmware, BMC & network fabric

OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427): slpd-lite is a small SLP responder that OpenBMC installs
Impact
slpd-lite is a small SLP responder that OpenBMC installs by default, and it overflows memory on crafted UDP packets. Because it is in the default build, this is not a niche configuration - if your image came from an OpenBMC tree and nobody explicitly removed the package, the daemon is listening. Unauthenticated remote memory corruption in a BMC-resident network daemon is the entry point that everything else in this cluster builds on: get code running on the BMC, then use the LPC-control or crypto kernel bugs to reach BMC root, then write flash and persist across tenant handover.
Who can reach it
Unauthenticated, network, UDP port 427 on the BMC's management interface. Nothing on the host and no credentials required. SLP is a discovery protocol nobody in a modern GPU fleet actually uses, which makes the exposure pure cost.
What to do
Two moves and the cheap one is very cheap. Config-only: block UDP 427 at the management-VLAN boundary and, better, remove slpd-lite from the image or stop and mask the service. It provides nothing an operator needs - Redfish discovery does not depend on it. The durable fix is upstream in the slpd-lite repository and reaches nodes through a BMC firmware flash: per node, out-of-band, ODM-lagged. Do the ACL and service disable now; batch the flash.
References
Related entries
- Linux kernel (drivers/infiniband/core): Tearing down an iWARP connection frees the rdma_id_private whileCVE-2024-42285 · Linux kernel (drivers/infiniband/core)Critical
- Rittal IoT Interface and CMC III Processing Unit - firmware upgrade signature check: The admin web interface verifiesCVE-2024-47943 · Rittal IoT Interface and CMC III Processing Unit - firmware upgrade signature checkCritical
- AMI MegaRAC SPx (Redfish Host Interface): Unauthenticated auth bypass, full BMC takeover, malicious firmware flash.CVE-2024-54085 · AMI MegaRAC SPx (Redfish Host Interface)Critical
- Linux bnxt_en driver (5760X / P7 aggregation ID mask): The bnxt_en driver mishandles the aggregation ID mask on 5760XCVE-2024-56656 · Linux bnxt_en driver (5760X / P7 aggregation ID mask)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): The driver advertises support for 13 scatter-gather entries per workCVE-2024-57936 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): A remote client corrupts kernel linked lists on the RDMA block-storageCVE-2025-21805 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.