Database/Kernel, userspace & hypervisor
AMD Pensando ionic cloud driver for VMware ESXi (heap overflow): Heap-based buffer overflow in the ionic SmartNIC
CVSS 8.8CVE-2025-62624Kernel, userspace & hypervisorcurated
Impact
Heap-based buffer overflow in the ionic SmartNIC driver on ESXi allowing privilege escalation and arbitrary code execution. The DPU driver sits in the hypervisor's network datapath, so compromise reaches all tenant traffic on the host.
Who can reach it
Local low-privilege access on the ESXi host; high attack complexity.
What to do
Apply the AMD-provided driver update per AMD-SB-2001. Driver VIB update plus host reboot - coordinate with any DPU firmware update in the same bulletin so you take one outage rather than two.
References
Related entries
- AMD Pensando ionic cloud driver for VMware ESXi (heap overflow): Second heap overflow in the ionic ESXi driverCVE-2025-62623 · AMD Pensando ionic cloud driver for VMware ESXi (heap overflow)High
- Linux kernel (drivers/iommu): This is the substantive fix for stale IOMMU translations of the kernel address spaceCVE-2025-71202 · Linux kernel (drivers/iommu)High
- KubeVirt virt-handler (symlink following in migration proxy): During live migration virt-handler dials Unix socketsCVE-2026-13622 · KubeVirt virt-handler (symlink following in migration proxy)High
- SSSD LDAP sudo provider: unscoped sudoRole search lets any LDAP writer grant themselves root fleet-wideCVE-2026-14474 · SSSD LDAP sudo provider (ldap_sudo_search_base unset)High
- Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is splitCVE-2026-31588 · Linux kernel (arch/x86/kvm)High
- Linux kernel (drivers/iommu/generic_pt): When an unmap lands in the middle of a large or contiguous page-table entryCVE-2026-31735 · Linux kernel (drivers/iommu/generic_pt)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.