Database/Firmware, BMC & network fabric
Dell Enterprise SONiC (OS command injection): OS command injection giving arbitrary command execution on the switch's
Impact
OS command injection giving arbitrary command execution on the switch's underlying Linux. Chained behind the authentication-bypass in the same advisory batch, an unauthenticated attacker goes from the network to root on the switch in two steps. On SONiC the 'switch' is a fairly normal Linux box with the ASIC SDK attached, so root there means arbitrary forwarding-table manipulation for every tenant on the device.
Who can reach it
Remote attacker holding high-privilege access — but see CVE-2024-45764, which supplies that access without credentials.
What to do
Same fix as the rest of DSA-2024-449: NOS image upgrade and reboot on every Dell Enterprise SONiC switch running 4.1.x or 4.2.x. Assume any device that was reachable pre-patch may hold persistence and consider a clean re-image rather than an in-place upgrade.
References
Related entries
- Dell Enterprise SONiC (privilege boundary in CLI): High-privilege OS commands can be run by users holding lessCVE-2024-45765 · Dell Enterprise SONiC (privilege boundary in CLI)Critical
- Arista EOS (OpenConfig gNOI authorization): The gNOI equivalent of the gNMI authorization bypass: operationsCVE-2025-1260 · Arista EOS (OpenConfig gNOI authorization)Critical
- Linux kernel - RDMA/rxe (Soft-RoCE) receive path, drivers/infiniband/sw/rxe/rxe_recv.c: Rxe_rcv() checked only that anCVE-2026-46043 · Linux kernel - RDMA/rxe (Soft-RoCE) receive path, drivers/infiniband/sw/rxe/rxe_recv.cCritical
- Linux kernel - SRP (SCSI RDMA Protocol) initiator, drivers/infiniband/ulp/srp/ib_srp.c: The SRP initiator copied theCVE-2026-53186 · Linux kernel - SRP (SCSI RDMA Protocol) initiator, drivers/infiniband/ulp/srp/ib_srp.cCritical
- Dell SmartFabric OS10 before 10.6.1.3: code downloaded without integrity check allows code executionCVE-2026-63696 · Dell SmartFabric OS10 (code download without integrity check)Critical
- Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCVE-2026-64269 · Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.