Database/Firmware, BMC & network fabric

AMI AptioV BIOS (unchecked buffer copy): Buffer copy without size checking in firmware leading to arbitrary code
CVSS 7.3CVE-2025-22833Firmware, BMC & network fabriccurated
Impact
Buffer copy without size checking in firmware leading to arbitrary code execution.
Who can reach it
Local low-privilege access with user interaction.
What to do
AMI ships the fix to OEMs, not to you - obtain the updated BIOS from your board/server vendor (Supermicro, Gigabyte, ASRock Rack, Quanta, Tyan etc.) and flash it. Expect a lag of weeks to months between the AMI advisory and an OEM image for your exact SKU, and expect some SKUs never to get one. Cold reboot per node.
References
Related entries
- AMD Secure Processor (ASP) bootloader - buffer overflow: A buffer overflow in the ASP bootloader gives an attacker aCVE-2025-29951 · AMD Secure Processor (ASP) bootloader - buffer overflowHigh
- Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR): Secure TSC is how an SEV-SNP guest gets a timebaseCVE-2025-38508 · Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR)High
- IBM Power Systems firmware: guest-partition root can write NVRAM that crashes the host firmware boot stageCVE-2026-17042 · IBM Power Systems host firmware (OpenPOWER NVRAM parsing)High
- Linux kernel (drivers/infiniband/hw/irdma): Queue-depth arithmetic was done in 32 bits, so a tenant passing a hugeCVE-2026-31491 · Linux kernel (drivers/infiniband/hw/irdma)High
- Dell OMSA: externally controlled class selection bypasses a protection mechanismCVE-2026-66269 · Dell OpenManage Server Administrator (unsafe reflection)High
- Dell OMSA: local low-privileged user reads sensitive information beyond the agent's scopeCVE-2026-80356 · Dell OpenManage Server Administrator (sensitive information exposure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.