Database/Firmware, BMC & network fabric

AmpereOne firmware: malformed SMC call to UEFI-MM MMCommunicate causes out-of-bounds write in the Secure Partition
Impact
An incorrectly formed SMC call into the UEFI-MM MMCommunicate service writes out of bounds inside the UEFI-MM Secure Partition context. That partition runs at a higher privilege than the host kernel and owns variable services and other platform state, so a successful write corrupts code or data that the operating system cannot inspect or defend against, and persistence below the OS is plausible. For Arm-based AmpereOne hosts used as head nodes, storage servers or accelerator hosts, this breaks the assumption that re-imaging a node returns it to a known state. Ampere's bulletin AMP-SB-0007 is the authority on exact exposure; the NVD record does not say which privilege level can issue the SMC, and the 9.8 network vector looks broader than an SMC-based local interface would normally allow.
Who can reach it
Issuing a malformed SMC to the UEFI-MM MMCommunicate service, which requires code execution on the host at a privilege level that can make SMC calls - in practice host kernel or firmware-level code. The NVD vector claims AV:N/PR:N; treat that with caution and read AMP-SB-0007 before concluding this is remotely reachable.
What to do
Flash fixed platform firmware: AmpereOne AC03 3.5.9.3 or later, AC04 4.4.5.2 or later, AmpereOne M 5.4.5.1 or later. This is a host firmware update, so each node must be drained and taken out of service for the flash and a power cycle - schedule it as a rolling maintenance window across the affected fleet. There is no OS-level mitigation.
References
Related entries
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): The inline copy path adds a page index where itCVE-2025-68811 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): svc_rdma_copy_inline_range indexes rq_pages with anCVE-2025-71068 · Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range)Critical
- Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointerCVE-2026-100075 · Linux kernel RDMA/srpt (SRP target, srpt_alloc_rw_ctxs unwind)Critical
- Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRFCVE-2026-20212 · Cisco Nexus 9000 NX-OS Silicon One integration (S1HAL, TCP 43210/43211)Critical
- Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handling: nvmet_tcp_build_pdu_iovec() walks pastCVE-2026-23112 · Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handlingCritical
- Linux kernel (drivers/infiniband/core): The iWARP connection manager returns work items to a free list while the sameCVE-2026-45898 · Linux kernel (drivers/infiniband/core)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.