Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management Mode
Impact
A write-what-where primitive plus an information leak in System Management Mode - the most privileged execution context on an x86 server, above the kernel and invisible to the hypervisor. An attacker who wins here can write anywhere in memory including SMRAM, disable firmware protections, and install a bootkit that persists across OS reinstall and survives every host-level detection you run. Scope is changed, so the compromise reaches beyond the BIOS into the running system. On a shared GPU host this defeats the boundary that VM isolation and confidential-computing attestation both rest on.
Who can reach it
Local, requires high privileges - root or kernel-level code on the host OS. So the precondition is that an attacker already owns the operating system on a node; this is what they use to convert a revocable OS compromise into permanent firmware residency. In a bare-metal GPU rental model, the tenant themselves have that privilege by design.
What to do
BIOS update to AptioV_5.040 or later. That is a firmware flash plus a full host reboot per node, which on a GPU fleet means draining the node - and if it is part of a multi-node training job, draining the whole ring. Rollout is gated on your server vendor picking up the AMI BKC and publishing a rebased BIOS for your specific SKU, which typically lags AMI's advisory by months. There is no config-only mitigation for an SMM bug. If you cannot patch, the compensating control is to stop treating host root as a containable compromise: rebuild affected nodes with a verified BIOS reflash rather than an OS reimage.
References
Related entries
- AMI AptioV UEFI BIOS (SMM): A memory-bounds bug in the BIOS that lets an attacker execute code outside the intendedCVE-2024-42442 · AMI AptioV UEFI BIOS (SMM)High
- Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adaptersCVE-2025-56547 · Broadcom NetXtreme-E network adapter firmwareHigh
- IBM Power Systems Firmware: BMC/FSP-to-host interface allows arbitrary code execution on the host systemCVE-2026-16930 · IBM Power Systems Firmware (BMC/FSP-to-host interface)High
- IBM Power Systems Firmware: BMC/FSP can read and write arbitrary host system memoryCVE-2026-16933 · IBM Power Systems Firmware (BMC/FSP-to-host memory interface)High
- IBM Power Systems Firmware: crafted configuration data from the BMC/FSP compromises the host boot stageCVE-2026-17093 · IBM Power Systems Firmware (host firmware configuration parsing)High
- IBM Power Systems Firmware: service processor mailbox allows code execution in host firmware runtimeCVE-2026-17100 · IBM Power Systems Firmware (service processor mailbox interface)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.