Database/Firmware, BMC & network fabric
Linux kernel mlx5_core firmware tracer (diag/fw_tracer): The firmware tracer took format strings directly from device
Impact
The firmware tracer took format strings directly from device firmware and passed them to kernel formatting with no validation. Malicious or compromised NIC/DPU firmware supplying %s, %p or %n reads arbitrary kernel memory. This is the clearest firmware-as-attacker case in the mlx5 stack, and it matters specifically for operators who accept hardware from third parties, run rented bare metal, or cannot fully attest NIC firmware provenance - the host kernel was trusting the device.
Who can reach it
Requires control of the NIC or DPU firmware image - a supply-chain or prior-tenant-persistence scenario on bare metal, or an attacker who already flashed the adapter. Not reachable from ordinary network traffic.
What to do
Upgrade the host kernel to 6.19 or a stable backport (5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, 6.18.3) - the fix restricts the tracer to integer and hex specifiers. Rolling reboot. Pair it with the real control: enforce signed firmware and re-flash adapters to a known-good version between bare-metal tenants.
References
Related entries
- Gigabyte UEFI firmware (SMM, unchecked RBX pointer): An attacker-controlled register is used as an unchecked pointerCVE-2025-7026 · Gigabyte UEFI firmware (SMM, unchecked RBX pointer)Unscored
- Gigabyte UEFI firmware (SMM, NVRAM double pointer dereference): An unvalidated NVRAM variable is dereferenced twiceCVE-2025-7027 · Gigabyte UEFI firmware (SMM, NVRAM double pointer dereference)Unscored
- Gigabyte UEFI firmware (SMM, unvalidated flash function pointers): Function pointer structures governing SPI flashCVE-2025-7028 · Gigabyte UEFI firmware (SMM, unvalidated flash function pointers)Unscored
- Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control): Unchecked register use lets the attacker controlCVE-2025-7029 · Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control)Unscored
- U-Boot: integer overflow in ZFS metadata parsing gives out-of-bounds access during bootCVE-2025-70290 · Das U-Boot (ZFS filesystem support, on-disk metadata parsing)Unscored
- libtpms (OpenSSL 3.x symmetric cipher IV handling): libtpms 0.10.0/0.10.1 built against OpenSSL 3.x returnedCVE-2026-21444 · libtpms (OpenSSL 3.x symmetric cipher IV handling)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.