Database/Firmware, BMC & network fabric

Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDs
Impact
An open, unauthenticated JTAG debug port on the drive's PCB exposes both main SoC CPU cores - and the enclosure cutout is wide enough that you do not even need to open the drive to reach it. With a cheap ARM JTAG probe an attacker executes arbitrary code on the controller, reads firmware and memory, and bypasses the RSA firmware signature check at boot. These are Kioxia's flagship DATACENTER drives; CM6/PM6/PM7 are standard fitment in the exact GPU and AI-server platforms this database is about. BREAKS TENANT HANDOFF and does it in the worst direction: an attacker who owns the controller can read everything regardless of Opal state, can make sanitize report success while preserving data, and can attempt to leave an implant that survives every reimage you perform. Note the researchers' own caveat - fully PERSISTENT firmware modification additionally requires a shared secret used to compute the firmware MAC, so persistence is not demonstrated as trivially achievable, but transient full control of the controller is.
Who can reach it
Anyone with brief physical access to the drive and a low-cost JTAG probe. The enclosure does not have to be opened, so this is minutes of unsupervised contact, not a lab teardown - a rack tech, a colo neighbour with cage access, a courier in the RMA path, a decommission handler, or anyone in the supply chain before the drive reached you.
What to do
UNPATCHABLE on the affected SKUs - the Google advisory records no fixed version, and an exposed JTAG pad is a board-design property that no firmware update removes. This is therefore a physical-security and procurement control, not a patch: enforce tamper-evident seals and chain of custody on CM6/PM6/PM7 media, never return or resell a drive that held tenant data (destroy it), and treat any of these drives with an unexplained custody gap as compromised at controller level rather than reimaging and re-renting it. Because you cannot trust the controller's own attestations on these drives, run LUKS/dm-crypt with an operator-held key so the drive only ever sees ciphertext and reclaim means destroying your key. Raise it with Kioxia as a procurement question for future SKUs - the fix has to come in hardware.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.