Database/Firmware, BMC & network fabric

ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c): Unbinding the LPC snoop driver tears
Impact
Unbinding the LPC snoop driver tears down channels that were never brought up, dereferencing NULL and panicking the BMC kernel. The reproducer is a single write to the driver's sysfs unbind file. Anyone with root on the BMC can hard-crash the management processor on demand; more usefully for an operator, it fires during ordinary driver reload and platform-teardown sequences, so it shows up as BMC instability on ASPEED platforms that only wire up a subset of the snoop channels.
Who can reach it
Root on the BMC (write access to the platform driver's sysfs bind/unbind), or any BMC-side maintenance flow that unbinds the driver. Not reachable from the host or the network on its own.
What to do
Kernel patch, backported to stable. Delivered only in a new BMC firmware image - per-node, out-of-band flash, gated on the ODM. Low priority as a standalone item; treat it as one more reason not to run BMC firmware images that are years behind upstream, and roll it in with the other lpc-snoop and video-engine fixes in a single flash rather than a dedicated campaign.
References
Related entries
- Linux crypto/ccp - SEV platform shutdown error handling: The ccp driver's SEV/SNP platform shutdown path couldCVE-2025-39936 · Linux crypto/ccp - SEV platform shutdown error handlingMedium
- Linux kernel RDMA core address resolution (RDMA_NL_LS_OP_IP_RESOLVE netlink handler): The netlink handler forCVE-2025-71096 · Linux kernel RDMA core address resolution (RDMA_NL_LS_OP_IP_RESOLVE netlink handler)Medium
- A shared library inside Supermicro BMC firmware that parses request headers: An authenticated attacker overflowsCVE-2025-8404 · A shared library inside Supermicro BMC firmware that parses request headersMedium
- Linux kernel (drivers/infiniband/hw/irdma): If copying the queue-pair response back to userspace fails, irdma'sCVE-2026-31492 · Linux kernel (drivers/infiniband/hw/irdma)Medium
- Linux KVM/SEV - vCPU locking when synchronizing VMSAs for SNP launch finish: KVM did not lock all vCPUsCVE-2026-31591 · Linux KVM/SEV - vCPU locking when synchronizing VMSAs for SNP launch finishMedium
- Linux KVM - VMSA sync on an already-launched SEV vCPU: KVM allowed synchronising vCPU state into the VMSACVE-2026-31593 · Linux KVM - VMSA sync on an already-launched SEV vCPUMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.