Database/Firmware, BMC & network fabric

uefi-firmware-parser: ReadCLen() overruns the 510-entry mCLen heap array on crafted firmware
Impact
ReadCLen() reads a 9-bit count and loops without enforcing Index < NC, so it can write 511 entries into the 510-element heap array Sd->mCLen, and the CharC == 2 run-length path can push up to 531 zero writes through the same index. A crafted Tiano or EFI compressed section therefore corrupts heap memory in any pipeline that parses untrusted firmware images - vendor BIOS or BMC bundles ingested for validation, attestation or inventory. The parse crashes deterministically and the advisory allows for code execution depending on build and runtime details, in the account that owns the firmware pipeline. This is a separate flaw from the stack overflow in MakeTable() (CVE-2026-54333): different function, different allocation, though both ship fixed in 1.14. No running node's firmware is affected.
Who can reach it
Anyone who can supply a crafted firmware image to a parsing run - a tampered vendor blob, an upload into a firmware analysis service, or automated ingest of third-party images.
What to do
Upgrade uefi-firmware-parser to 1.14, which bounds the mCLen loop. A library bump and a restart of the importing service or job; no node or firmware maintenance. Meanwhile restrict parsing to trusted image sources and isolate the parser from firmware repositories and signing keys.
References
Related entries
- Dell SmartFabric OS10 before 10.6.1.3: session fixation lets a remote unauthenticated attacker steal a sessionCVE-2026-63695 · Dell SmartFabric OS10 (session handling in the management interface)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: The siw receive path decodesCVE-2026-64102 · Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.c: Siw places inbound Read Response segmentsCVE-2026-64268 · Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.c: Nvmet_rdma_use_inline_sg() accepted any host-controlledCVE-2026-72129 · Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.cCritical
- Linux kernel (drivers/infiniband/hw/irdma): The driver signalled completion of control-plane requests through anCVE-2026-72494 · Linux kernel (drivers/infiniband/hw/irdma)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.