Database/Firmware, BMC & network fabric
Lenovo ThinkSystem UEFI/BIOS (SMM callout): A System Management Mode callout vulnerability in ThinkSystem UEFI
Impact
A System Management Mode callout vulnerability in ThinkSystem UEFI - SMM code calls out to memory it does not control, letting a local attacker with elevated privileges execute code in SMM. SMM sits above the hypervisor and is invisible to it, so this is a persistent-implant primitive: what an attacker installs there is not removed by reimaging, disk replacement or hypervisor reinstall. The affected list runs to roughly 99 platforms and explicitly includes the GPU boxes - SR670 V2 and SR675 V3 - alongside SR630/SR650/SR645/SR665 V3 and the ThinkAgile appliances.
Who can reach it
Local to the host with elevated privileges - root or administrator on the operating system. Not reachable from the management VLAN; the path is a tenant or workload that already holds privileged host access.
What to do
UEFI/BIOS update on each affected node, per the per-model version table in LEN-165524. This is the expensive kind: the payload can be staged through XCC, but it applies only on the next host reboot, so it needs a drain of running training jobs and a maintenance window per node. For SR670 V2 / SR675 V3 GPU nodes that is real lost capacity - plan it as a rolling campaign against spare capacity, not an emergency sweep. No config-only mitigation exists for an SMM defect.
References
Related entries
- Lenovo ThinkSystem / ThinkStation (firmware buffer overflow): A local attacker with elevated privileges executesCVE-2024-4550 · Lenovo ThinkSystem / ThinkStation (firmware buffer overflow)Medium
- GRUB2 (JPEG parser): Out-of-bounds write in GRUB's JPEG parser from a crafted imageCVE-2024-45774 · GRUB2 (JPEG parser)Medium
- GRUB2 (commands/extcmd): A failed allocation goes unchecked, so GRUB proceeds on a NULL pointer and its stateCVE-2024-45775 · GRUB2 (commands/extcmd)Medium
- GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruptionCVE-2024-45778 · GRUB2 (BFS filesystem parser)Medium
- GRUB2 (tar filesystem parser): Integer overflow in the tarfs module writes out of boundsCVE-2024-45780 · GRUB2 (tar filesystem parser)Medium
- GRUB2 (UFS filesystem parser): Symlink name length is never validated, giving a heap out-of-bounds write in the UFSCVE-2024-45781 · GRUB2 (UFS filesystem parser)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.