Database/Firmware, BMC & network fabric

AMI AptioV BIOS (TOCTOU race condition): Firmware TOCTOU race allowing execution of arbitrary code on the target device
CVSS 7.5CVE-2024-42444Firmware, BMC & network fabriccurated
Impact
Firmware TOCTOU race allowing execution of arbitrary code on the target device.
Who can reach it
Local low-privilege access with user interaction.
What to do
AMI ships the fix to OEMs, not to you - obtain the updated BIOS from your board/server vendor (Supermicro, Gigabyte, ASRock Rack, Quanta, Tyan etc.) and flash it. Expect a lag of weeks to months between the AMI advisory and an OEM image for your exact SKU, and expect some SKUs never to get one. Cold reboot per node.
References
Related entries
- AMI AptioV BIOS (TOCTOU race condition): Second firmware TOCTOU race reaching arbitrary code execution with scope changeCVE-2024-42446 · AMI AptioV BIOS (TOCTOU race condition)High
- GRUB2 (gettext / message catalogue): Integer overflow reading a crafted translation catalogue gives bothCVE-2024-45776 · GRUB2 (gettext / message catalogue)High
- GRUB2 (gettext / message catalogue): Second integer overflow in the same translation path, producing a heapCVE-2024-45777 · GRUB2 (gettext / message catalogue)High
- GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed bufferCVE-2024-45782 · GRUB2 (HFS filesystem parser)High
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server trusts a connecting client to send its session-info messageCVE-2024-50062 · Linux kernel (drivers/infiniband/ulp/rtrs)High
- Linux kernel (drivers/infiniband/core): A peer that drives enough connection churn across a node's IB port pushes theCVE-2024-50095 · Linux kernel (drivers/infiniband/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.