Database/Firmware, BMC & network fabric
Dell iDRAC Service Module (iSM): Buffer access with incorrect length in the in-band agent gives a low-privileged local
Impact
Buffer access with incorrect length in the in-band agent gives a low-privileged local attacker code execution and elevation on the host OS. iSM is the bridge between host and BMC, so it is a stepping stone from tenant workload toward out-of-band control.
Who can reach it
Any low-privilege local account on the server OS - including a container that escaped to the host.
What to do
Upgrade iSM to 6.0.3.0. Host package update plus service restart, no reboot and no firmware flash. Cheap - do it in the normal patch cycle. If you do not actually consume iSM telemetry, uninstall it instead.
References
Related entries
- Linux bnxt_en driver (ring defaults vs traffic classes on ifdown): Memory corruption when firmware resources changeCVE-2025-39810 · Linux bnxt_en driver (ring defaults vs traffic classes on ifdown)High
- Linux kernel (drivers/infiniband/sw/rxe): Use-after-free from a race between a busy soft-RoCE task and its ownCVE-2025-40061 · Linux kernel (drivers/infiniband/sw/rxe)High
- The Linux kernel's IPMI driver message-handling layer: A use-after-free in a kernel driver reachable from the host'sCVE-2025-40202 · The Linux kernel's IPMI driver message-handling layerHigh
- Eaton UPS Companion (EUC) executable - library loading: Insecure library loading in the shipped executable givesCVE-2025-67450 · Eaton UPS Companion (EUC) executable - library loadingHigh
- Linux kernel (drivers/infiniband/sw/rxe): Two failed shared-receive-queue resizes in a row panic the node. The firstCVE-2025-68379 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel mlxsw (Spectrum switch router, neighbour table): The driver stored neighbour pointers without holdingCVE-2025-68801 · Linux kernel mlxsw (Spectrum switch router, neighbour table)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.