Database/Firmware, BMC & network fabric

IBM OpenBMC: host can crash the BMC firmware management service or read BMC internal memory
Impact
A compromised or malicious host OS can reach the BMC's firmware management interface and either crash that service or read a limited amount of BMC internal memory. This is a host-to-BMC crossing: the BMC is the out-of-band control path an operator relies on to reset, reimage or power-cycle a node whose host is already untrusted, so losing the firmware management service removes the recovery channel exactly when it is needed. The memory disclosure is limited in scope but sits in the component that handles firmware images. Affected IBM OpenBMC levels are FW1120.00-FW1120.01, FW1110.00-FW1110.31 and FW1060.00-FW1060.81 on IBM Power S1122/S1124 class systems; impact is confidentiality and availability only, no code execution is claimed.
Who can reach it
The host system attached to the BMC - requires high privilege on that host (root or equivalent, able to drive the host-BMC interface). Not reachable from the management network by an unauthenticated attacker.
What to do
Apply the IBM firmware update for your level per IBM support document 7289253. BMC/system firmware updates on Power systems mean taking the node out of service for the flash and a controlled restart, so schedule it in a maintenance window rather than treating it as a live patch. Interim mitigation is the usual one: keep host root trusted and the BMC off any tenant-reachable path.
References
Related entries
- AMD SEV guest VMs - TLB flush after VMCB creation sequence: The CPU may fail to flush the TLB after a particularCVE-2021-26342 · AMD SEV guest VMs - TLB flush after VMCB creation sequenceLow
- AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): A use-after-free inCVE-2023-20519 · AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002)Low
- Intel TDX firmware (PRNG seeding): A predictable seed in the TDX firmware's pseudo-random number generator. PredictableCVE-2025-20613 · Intel TDX firmware (PRNG seeding)Low
- AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptionsCVE-2023-20573 · AMD SEV-SNP - debug exception delivery to guestsLow
- AMD CPU microcode - RDRAND entropy after patch load: Incomplete cleanup after loading a microcode patch degrades theCVE-2024-21977 · AMD CPU microcode - RDRAND entropy after patch loadLow
- AMD CPU cache initialization - SEV-SNP guest memory integrity: Improper initialization of CPU cache memory lets aCVE-2024-36331 · AMD CPU cache initialization - SEV-SNP guest memory integrityLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.