Database/Firmware, BMC & network fabric

IBM PowerVM partition firmware: malformed network-boot packet yields code execution inside the booting partition
Impact
An attacker on the same network segment as a partition that is performing a network boot can send a malformed packet and execute arbitrary code in that partition's firmware. Because the compromise lands below the operating system, everything the partition subsequently loads - kernel, initramfs, accelerator drivers, workload - is loaded by code the attacker controls, and nothing the guest OS later checks can attest to its own boot. IBM states that other partitions and the managed system itself are not affected, which bounds the blast radius to the partition being booted. On Power systems used as accelerator hosts this matters most for fleets that netboot nodes as part of a reimage or drain-and-rebuild cycle, since that is exactly the window in which the partition is exposed.
Who can reach it
Adjacent network - an attacker with a presence on the same network as the partition while it is actively network booting. No authentication required, but IBM rates attack complexity high and a partition not netbooting is not exposed.
What to do
Apply the Power Systems Firmware fix from IBM's advisory for the affected levels (FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2); this is a system firmware update, so plan it as a maintenance window with the affected partitions out of service. Until firmware is applied, the practical mitigation is to keep the network-boot path on a segment no untrusted host can reach, and to avoid netbooting over shared or tenant-reachable networks.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.