Database/Firmware, BMC & network fabric

EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling): A malicious iSCSI target sends a crafted R2T PDU
Impact
A malicious iSCSI target sends a crafted R2T PDU with a bogus offset and length, and the booting firmware obligingly transmits chunks of its own memory back to the target. Low severity on paper, and it is a read-only leak, but what leaks is DXE-phase memory - boot secrets, variable contents, buffer addresses - which is exactly the reconnaissance an attacker needs before firing one of the higher-severity overflow bugs in the same stack.
Who can reach it
An attacker controlling or impersonating the iSCSI target a node boots from. Unauthenticated, pre-OS, from the storage network.
What to do
OEM BIOS update, flash + reboot per node - but given the low score, do not expect OEMs to ship it urgently or to call it out prominently in release notes. The config workaround is the better first move: turn off the UEFI iSCSI initiator on nodes that boot locally, require mutual CHAP where you do boot from SAN, and segment the storage fabric.
References
Related entries
- Dell iDRAC9 / iDRAC10 (memory erase, data remanence): Data survives an iDRAC memory erase and stays readableCVE-2026-70412 · Dell iDRAC9 / iDRAC10 (memory erase, data remanence)Low
- IBM OpenBMC: host can crash the BMC firmware management service or read BMC internal memoryCVE-2026-18857 · IBM OpenBMC (BMC firmware management interface)Low
- AMD SEV guest VMs - TLB flush after VMCB creation sequence: The CPU may fail to flush the TLB after a particularCVE-2021-26342 · AMD SEV guest VMs - TLB flush after VMCB creation sequenceLow
- AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): A use-after-free inCVE-2023-20519 · AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002)Low
- Intel TDX firmware (PRNG seeding): A predictable seed in the TDX firmware's pseudo-random number generator. PredictableCVE-2025-20613 · Intel TDX firmware (PRNG seeding)Low
- AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptionsCVE-2023-20573 · AMD SEV-SNP - debug exception delivery to guestsLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.