Database/Firmware, BMC & network fabric
Intel Ethernet Network Adapter E810 (100GbE) firmware: Out-of-bounds read in 100GbE E810 firmware reachable
Impact
Out-of-bounds read in 100GbE E810 firmware reachable from privileged host software, causing denial of service. The version threshold here (cvl fw 1.7.6, cpk 1.3.7) is different again from the other E810 advisories — the E810 firmware CVE trail is long enough that version-by-CVE tracking is not workable and operators should treat it as a rolling minimum-version policy.
Who can reach it
Privileged local software on the host (Ring 0).
What to do
Flash E810 firmware to at least cvl fw 1.7.6 / cpk 1.3.7 — and given the later advisories, go straight to 1.7.8.x or newer. Cold power cycle, per node.
References
Related entries
- Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotelyCVE-2025-36608 · Dell SmartFabric OS10 (XML external entity)Medium
- Linux kernel (drivers/infiniband/core): Bursts of network neighbour updates crash the node. Each event re-initializes aCVE-2025-37772 · Linux kernel (drivers/infiniband/core)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): All IPsec offload objects on a physical function shareCVE-2026-23441 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel)Medium
- Linux kernel RDS over InfiniBand (FRMR registration before connection establishment): An RDS sendmsg carryingCVE-2026-31425 · Linux kernel RDS over InfiniBand (FRMR registration before connection establishment)Medium
- HPE iLO 6 (denial of service): An unauthenticated attacker on an adjacent network can knock out iLO 6 availabilityCVE-2026-63457 · HPE iLO 6 (denial of service)Medium
- Dell OpenManage Enterprise: XML external entity processing exposes information to a low-privileged userCVE-2026-70423 · Dell OpenManage Enterprise (XML external entity processing)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.