Database/Control plane, storage & DevOps

Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSA
Impact
Electromagnetic side channel in Infineon's ECDSA implementation allows secret key extraction from affected security chips. The library is used well beyond the headline YubiKey case, across Infineon security microcontrollers that also serve as TPMs and platform root-of-trust devices. Where such a chip anchors a fleet's attestation or admin authentication, a cloned credential is indistinguishable from the real one.
Who can reach it
Physical access plus specialised equipment and time with the device. In a datacenter this is not automatically out of scope: a colo cage, an RMA path, a decommissioning contractor, or remote-hands staff all supply that access, and hardware in transit is the classic exposure window.
What to do
Chip firmware cannot be updated in the affected devices - the fix ships only in new hardware revisions. So the answer is inventory, then replacement or acceptance, plus rotating any credential the affected chip holds. For an operator, the practical control is chain-of-custody: tamper-evident sealing, tracked RMA handling, and never returning a root-of-trust device to a pool without re-provisioning.
References
Related entries
- Slurm (slurmdbd accounting, Coordinator role): A Coordinator - the delegated role a site gives a team lead over theirCVE-2025-43904 · Slurm (slurmdbd accounting, Coordinator role)Medium
- HTCondor (condor_schedd / Access Point): A user plants a specially crafted job that lies dormant, then runs as aCVE-2025-66433 · HTCondor (condor_schedd / Access Point)Medium
- Sealed Secrets controller: unauthenticated template oracle recovers sealed secret plaintextCVE-2026-59341 · Bitnami Sealed Secrets controller (/v1/verify and /v1/rotate HTTP endpoints)Medium
- Apache Airflow 3.3.0-3.3.1: cookie wins over explicit bearer token, misattributing API calls and audit recordsCVE-2026-82355 · Apache Airflow core API (session cookie vs bearer token precedence)Medium
- Jenkins core: build CLI -s flag cancels other users' builds without the Item/Cancel permissionCVE-2026-84657 · Jenkins core (build CLI command, -s flag skips Item/Cancel check)Medium
- AMD IOMMU register interface - ASP coherency: Improper access control on the IOMMU register interface lets a privilegedCVE-2025-54509 · AMD IOMMU register interface - ASP coherencyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.