Database/Firmware, BMC & network fabric
Dell iDRAC Service Module (iSM) for Windows and Linux: Improper access control in the host-side iDRAC Service Module
Impact
Improper access control in the host-side iDRAC Service Module lets a low-privilege local user escalate on the host. iSM is the agent that bridges the operating system to the iDRAC over the internal USB-NIC / passthrough channel, so it is the component that deliberately crosses the host-to-BMC boundary. Escalating through it gets an attacker host-level privilege and puts them next to a channel that talks to the service processor - the pivot direction that turns a tenant workload compromise into an out-of-band one. Affects iSM for Windows before 6.0.3.1 and iSM for Linux before 5.4.1.1.
Who can reach it
Host-side, local, low privilege - a tenant workload or any account on the operating system where iSM is installed. Not reachable from the management VLAN; the exposure is entirely inside the host.
What to do
Upgrade the iSM package on the host to 6.0.3.1 (Windows) or 5.4.1.1 (Linux) or later. This is a host-side package update and a service restart, not a firmware flash - no host reboot in the normal case, so no job drain. Config-only alternative worth considering on nodes that do not need it: uninstall iSM entirely, or disable the iDRAC host USB-NIC passthrough (iDRAC Settings > OS to iDRAC Pass-through), which removes the host-to-BMC channel at the cost of in-band iDRAC access and some OS-level telemetry.
References
Related entries
- Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path): When mapping a dmabuf-backed RDMA memory region failsCVE-2026-43128 · Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path)High
- Linux bnxt_en driver (RSS context delete logic): RSS contexts are not always freed in firmware when the driver deletesCVE-2026-43260 · Linux bnxt_en driver (RSS context delete logic)High
- Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init): If the copy_to_user() that returns the SRQCVE-2026-45852 · Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init)High
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE retransmit and ack timers race against queue-pair destructionCVE-2026-45910 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure): Once __rds_rdma_map() has handed theCVE-2026-46053 · Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure)High
- Linux kernel (drivers/infiniband/hw/mana): The userspace ABI lets a tenant point several work queues at the sameCVE-2026-46117 · Linux kernel (drivers/infiniband/hw/mana)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.