Database/Firmware, BMC & network fabric

Gigabyte UEFI firmware (SMM, unvalidated flash function pointers): Function pointer structures governing SPI flash
Impact
Function pointer structures governing SPI flash operations are not validated, so an attacker in SMM context can redirect the routines that read, write and erase the platform firmware. This is the worst of the four: it hands the attacker the flash-write primitive directly, meaning a permanent bootkit rather than a runtime compromise.
Who can reach it
Local privileged code on the host.
What to do
Gigabyte BIOS update per board plus reboot. Because the payoff is a flash write, assume any node you believe was compromised needs firmware re-flashed from a known-good image and its integrity independently verified - a BIOS update applied by a compromised system does not prove anything. For high-value nodes, external SPI verification is the only real assurance.
References
Related entries
- Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control): Unchecked register use lets the attacker controlCVE-2025-7029 · Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control)Unscored
- U-Boot: integer overflow in ZFS metadata parsing gives out-of-bounds access during bootCVE-2025-70290 · Das U-Boot (ZFS filesystem support, on-disk metadata parsing)Unscored
- libtpms (OpenSSL 3.x symmetric cipher IV handling): libtpms 0.10.0/0.10.1 built against OpenSSL 3.x returnedCVE-2026-21444 · libtpms (OpenSSL 3.x symmetric cipher IV handling)Unscored
- Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP)CVE-2026-34878 · Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP) containerUnscored
- Linux kernel IPMI: refcount leak on the supplied-recv error path permanently pins the IPMI userCVE-2026-72040 · Linux kernel IPMI driver (i_ipmi_request supplied-recv error path)Unscored
- Linux kernel i2c-mlxbf (BlueField DPU I2C controller): mlxbf_i2c_init_resource() frees a resource struct and then readsCVE-2026-72140 · Linux kernel i2c-mlxbf (BlueField DPU I2C controller)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.