Database/Firmware, BMC & network fabric

Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1
Impact
A malformed SMC from the normal world produces an out-of-bounds write inside the S-EL0 UEFI-MM secure partition. That is code execution in the secure world reached from the OS - the boundary AmpereOne uses to protect runtime firmware services. Once there, the attacker can rewrite firmware state, forge attestation, or persist across a tenant handoff. The bulletin's siblings give a secure-partition-context OOB write (CVE-2025-62864) and an S-EL0 info leak (CVE-2025-62862), so the whole SMC surface should be treated as compromised until patched.
Who can reach it
Host kernel or hypervisor issuing SMC calls on an AmpereOne node. On bare-metal AmpereOne rental this is the tenant. No physical or network access needed.
What to do
Update to the fixed firmware for your part - AC03 3.5.9.3, AC04 4.4.5.2, AmpereOne M 5.4.5.1 - from the board OEM. Flash + reboot + drain per node; because this is in UEFI-MM, it ships as part of the platform firmware bundle and the ODM must integrate Ampere's release before you can install it. Verify the running version after reboot; AmpereOne firmware version strings are per-SKU and easy to get wrong on a mixed fleet.
References
Related entries
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): The inline copy path adds a page index where itCVE-2025-68811 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): svc_rdma_copy_inline_range indexes rq_pages with anCVE-2025-71068 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointerCVE-2026-100075 · Linux kernel RDMA/srpt (SRP target, srpt_alloc_rw_ctxs unwind)Critical
- Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRFCVE-2026-20212 · Cisco Nexus 9000 NX-OS Silicon One integration (S1HAL, TCP 43210/43211)Critical
- Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handling: nvmet_tcp_build_pdu_iovec() walks pastCVE-2026-23112 · Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handlingCritical
- Linux kernel (drivers/infiniband/core): The iWARP connection manager returns work items to a free list while the sameCVE-2026-45898 · Linux kernel (drivers/infiniband/core)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.