Database/Firmware, BMC & network fabric
Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed array
Impact
The async-event handler indexes a fixed array with a type field supplied by the NIC firmware, without bounds checking — so firmware controls a kernel array index. This is the concrete version of a threat operators often wave at abstractly: if the adapter's firmware is compromised or buggy, it has a direct path into kernel memory corruption on the host. Every argument for verifying NIC firmware provenance at intake rests on bugs of exactly this shape.
Who can reach it
The NIC firmware itself, or anything that can influence what the firmware reports — which includes a firmware image installed at build time or by a previous tenant on bare metal.
What to do
Kernel/driver upgrade plus host reboot. The durable control is separate: verify and reflash NIC firmware from a known-good image at rack intake and at tenant handoff, so the host is not trusting whatever firmware happens to be on the card.
References
Related entries
- Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPCCVE-2026-33800 · Juniper Junos OS on MX Series (Packet Forwarding Engine, PFEMAN micro-BFD event processing)High
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsCVE-2026-35155 · Dell iDRAC10 (credential handling, race condition)High
- Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straightCVE-2026-45856 · Linux kernel InfiniBand core (ib_uverbs post_send)High
- Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation): The cpu_id a tenant passes whenCVE-2026-53187 · Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation)High
- Dell OpenManage Enterprise: SQL injection reachable by a low-privileged remote userCVE-2026-56088 · Dell OpenManage Enterprise (web console, SQL injection)High
- Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad): This is a pre-authentication flaw on theCVE-2026-68425 · Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.