Database/Firmware, BMC & network fabric
AMD Pensando ionic driver on ESXi: untrusted pointer dereference lets a guest VM read kernel and co-tenant memory
Impact
An untrusted pointer dereference in the ionic cloud driver gives an unprivileged VM a path to read ESXi kernel memory or the memory of other VMs sharing the host. On a DPU-offloaded GPU host that breaks the tenant boundary at the layer operators lean on most heavily: the DPU terminates the network datapath for every VM on the box, so one tenant VM reading across it can reach keys, tokens and in-flight data belonging to neighbouring workloads. AMD also notes a potential availability impact, which on a DPU means losing the host's networking rather than a single guest. Affects ESXi 8.x and 9.x hosts using AMD-Pensando DPU products.
Who can reach it
A local attacker inside an unprivileged guest VM on an affected ESXi host. No host credentials and no management-network access required; AMD rates attack complexity high.
What to do
Apply the driver/firmware updates listed in AMD bulletin AMD-SB-2001 for the affected ESXi versions. Replacing an ionic driver on ESXi means putting the host into maintenance mode, evacuating or shutting down its VMs, installing the VIB and rebooting - a full drain of the host, which is expensive on a GPU node with pinned, long-running jobs. Check the bulletin for the exact fixed driver and DPU firmware versions for your ESXi build before scheduling the window.
References
Related entries
- Supermicro BMC firmware validation (MBD-X12STW): RoT bypass, crafted firmware image acceptedCVE-2025-7937 · Supermicro BMC firmware validation (MBD-X12STW)High
- Supermicro BMC web server request handling on MBD-X13SEDW-F: Any account that can log into the BMC web interface canCVE-2025-8076 · Supermicro BMC web server request handling on MBD-X13SEDW-FHigh
- Supermicro BMC web interface (stack buffer overflow, X13SEDW-F): Second authenticated stack overflow in the BMC webCVE-2025-8727 · Supermicro BMC web interface (stack buffer overflow, X13SEDW-F)High
- Perle IOLAN STS/SCS terminal server (firmware before 6.0): A logged-in user of the restricted admin shell (TelnetCVE-2026-23759 · Perle IOLAN STS/SCS terminal server (firmware before 6.0)High
- Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boards: Crafted characters injectedCVE-2026-3820 · Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boardsHigh
- Dell OMSA: high-privileged remote user escalates beyond their assigned OMSA roleCVE-2026-81445 · Dell OpenManage Server Administrator (privilege management, admin-level)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.