Database/Firmware, BMC & network fabric

AMI AptioV UEFI firmware: incomplete input validation lets a privileged local user execute code in firmware context
Impact
A privileged local user can reach a BIOS interface that does not reject all disallowed inputs and from there execute arbitrary code, with confidentiality, integrity and availability impact and a scope change past the OS boundary in AMI's own scoring. AptioV is the UEFI firmware shipped by many x86 server OEMs, so this is the layer underneath the hypervisor and the GPU driver on a large share of a fleet: code that lands there survives reinstalling the host and is not visible to anything running above it. For a GPU node that means a host-root compromise can be converted into persistence that a reimage does not clear, and the only honest recovery is a firmware reflash. AMI does not publish per-platform detail; which servers are affected depends on the OEM's BIOS build.
Who can reach it
Local access with high privilege (CVSS AV:L/PR:H) - in practice root or Administrator on the host, or anyone with the equivalent through an out-of-band firmware update path. Not reachable from a tenant workload that lacks host privilege. Attack requirements are marked present (AT:P), so exploitation is not unconditional.
What to do
There is no fix you apply directly from AMI - wait for the BIOS release from your server OEM that picks up the AMI-SA-2026001 fix, then flash it. That means the node comes out of service: drain the workloads, flash BIOS, reboot, and revalidate GPU and fabric enumeration before returning it to the pool. Track it per platform, since OEMs pick up AptioV fixes on their own schedules and some SKUs will not get a build.
References
Related entries
- Linux kernel mlx5_core eswitch / vport (SR-IOV): Mlx5_core sizes a firmware command buffer from the physical function'sCVE-2026-53230 · Linux kernel mlx5_core eswitch / vport (SR-IOV)High
- Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switchCVE-2017-3883 · Cisco FXOS / NX-OS AAAHigh
- Cisco NX-OS PTP feature (Nexus 5500/5600/6000): An unauthenticated remote attacker takes down a Nexus switch throughCVE-2018-0378 · Cisco NX-OS PTP feature (Nexus 5500/5600/6000)High
- Cisco NX-OS (VXLAN OAM / NGOAM): A crafted VXLAN OAM packet reloads a VTEP. In a VXLAN/EVPN GPU fabric every leaf is aCVE-2021-1587 · Cisco NX-OS (VXLAN OAM / NGOAM)High
- Intel Ethernet Adapter manageability firmware (NC-SI / sideband path): Improper input validation in the *manageability*CVE-2021-33141 · Intel Ethernet Adapter manageability firmware (NC-SI / sideband path)High
- GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB fontCVE-2022-2601 · GRUB2 (font engine, grub_font_construct_glyph)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.