Database/Firmware, BMC & network fabric

uefi-firmware-parser: unvalidated bit lengths in MakeTable() smash the stack on crafted firmware
Impact
MakeTable() in the Tiano decompressor does not check that bit-length values read from the compressed bitstream fall in the expected 0-16 range, so a crafted Tiano or EFI compressed section drives writes past the stack-allocated Count[17] array and the neighbouring decode tables. This matters to operators who parse firmware images they did not build - vendor BIOS/BMC bundles pulled into an automated validation, attestation or inventory pipeline. The parsing process crashes deterministically, and the advisory states code execution may be possible depending on build and runtime hardening; code execution would land in whatever account that pipeline runs as, typically one holding the firmware images for the whole fleet. Nothing here affects firmware on a running node - the exposure is the tooling, not the platform.
Who can reach it
Anyone who can get a crafted firmware image into a parsing run: an untrusted or tampered vendor blob, a file upload into a firmware analysis service, or any automated ingest of third-party images. No authentication is implied beyond the ability to supply the file.
What to do
Upgrade uefi-firmware-parser to 1.14, which adds the range check. This is a library bump plus a restart of whatever service or job imports it - no node, fleet or firmware action is involved. Until then, parse only images whose source you trust and run the parser in a sandbox with no access to firmware repositories or signing material.
References
Related entries
- uefi-firmware-parser: ReadCLen() overruns the 510-entry mCLen heap array on crafted firmwareCVE-2026-54334 · uefi-firmware-parser Tiano decompressor (ReadCLen mCLen bounds)Critical
- Dell SmartFabric OS10 before 10.6.1.3: session fixation lets a remote unauthenticated attacker steal a sessionCVE-2026-63695 · Dell SmartFabric OS10 (session handling in the management interface)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: The siw receive path decodesCVE-2026-64102 · Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.c: Siw places inbound Read Response segmentsCVE-2026-64268 · Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.c: Nvmet_rdma_use_inline_sg() accepted any host-controlledCVE-2026-72129 · Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.