Database/Firmware, BMC & network fabric

ASPEED crypto/ACRY accelerator driver (drivers/crypto/aspeed): The ACRY driver's probe error path and its remove path
Impact
The ACRY driver's probe error path and its remove path both hand-free a clock that the device-managed allocator will free again, giving a double free in the BMC kernel. It sits in the crypto accelerator the BMC uses for TLS and firmware signature work, which is the wrong place to have allocator corruption: a double free in a driver that touches signing and TLS paths is the kind of primitive that turns into controlled kernel memory reuse rather than just a crash. Realistic near-term impact is BMC kernel instability during driver load failures or module removal.
Who can reach it
BMC-local. Reached through driver probe failure or an explicit driver removal, so it needs root on the BMC or a boot-time condition that makes probe fail. Not host- or network-reachable directly.
What to do
Kernel fix, backported into 6.6.117, 6.12.58 and 6.17.8 and later. In practice: BMC firmware flash per node, out-of-band, whenever your ODM rebases - which for a fix this recent will realistically be a full release cycle away. No config mitigation; the crypto driver is loaded because bmcweb's TLS wants it. Track it, do not run a special campaign for it.
References
Related entries
- Linux kernel mlx5_core firmware tracer (diag/fw_tracer): The firmware tracer took format strings directly from deviceCVE-2025-68816 · Linux kernel mlx5_core firmware tracer (diag/fw_tracer)Unscored
- Gigabyte UEFI firmware (SMM, unchecked RBX pointer): An attacker-controlled register is used as an unchecked pointerCVE-2025-7026 · Gigabyte UEFI firmware (SMM, unchecked RBX pointer)Unscored
- Gigabyte UEFI firmware (SMM, NVRAM double pointer dereference): An unvalidated NVRAM variable is dereferenced twiceCVE-2025-7027 · Gigabyte UEFI firmware (SMM, NVRAM double pointer dereference)Unscored
- Gigabyte UEFI firmware (SMM, unvalidated flash function pointers): Function pointer structures governing SPI flashCVE-2025-7028 · Gigabyte UEFI firmware (SMM, unvalidated flash function pointers)Unscored
- Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control): Unchecked register use lets the attacker controlCVE-2025-7029 · Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control)Unscored
- U-Boot: integer overflow in ZFS metadata parsing gives out-of-bounds access during bootCVE-2025-70290 · Das U-Boot (ZFS filesystem support, on-disk metadata parsing)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.