Database/Firmware, BMC & network fabric

U-Boot: integer overflow in ZFS metadata parsing gives out-of-bounds access during boot
Impact
Malformed ZFS on-disk metadata causes an incorrect allocation size and a subsequent out-of-bounds memory access while the bootloader reads the filesystem, which the report describes as a crash or possible code execution during boot. Exposure is narrow: U-Boot is the boot firmware on BMCs, ARM server platforms and DPUs rather than on typical x86 GPU hosts, the ZFS reader has to be compiled into the image, and the attacker needs to control the pool U-Boot reads. What keeps it worth tracking is the stage it runs at, before any operating system integrity control exists. Fixed in U-Boot 2026.04.
Who can reach it
Someone able to write the boot media or ZFS pool that U-Boot reads at startup: physical access, a compromised provisioning path, or an attacker-controlled boot source. No authentication exists at this stage.
What to do
Move to U-Boot 2026.04 or later where the platform vendor ships it; on BMCs, DPUs and appliances that means waiting for a vendor firmware image and flashing the device with the node out of service. Builds without ZFS support are not affected. Note the record carries no vendor advisory or upstream commit, only the NVD entry and the reporter's writeup, so no per-platform fixed firmware level is known.
References
Related entries
- libtpms (OpenSSL 3.x symmetric cipher IV handling): libtpms 0.10.0/0.10.1 built against OpenSSL 3.x returnedCVE-2026-21444 · libtpms (OpenSSL 3.x symmetric cipher IV handling)Unscored
- Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP)CVE-2026-34878 · Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP) containerUnscored
- Linux kernel IPMI: refcount leak on the supplied-recv error path permanently pins the IPMI userCVE-2026-72040 · Linux kernel IPMI driver (i_ipmi_request supplied-recv error path)Unscored
- Linux kernel i2c-mlxbf (BlueField DPU I2C controller): mlxbf_i2c_init_resource() frees a resource struct and then readsCVE-2026-72140 · Linux kernel i2c-mlxbf (BlueField DPU I2C controller)Unscored
- Linux kernel mlxsw: failed LAG index allocation leaks a LAG reference on Spectrum switchesCVE-2026-72308 · Linux kernel mlxsw (Spectrum switch driver, LAG join error path)Unscored
- Linux kernel bnxt_re: uninitialised shared page mapped to userspace leaks kernel memoryCVE-2026-74584 · Linux kernel bnxt_re RDMA driver (ucontext shared page)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.