Database/Control plane, storage & DevOps

DMTF SPDM specification DSP0274 1.4 (FINISH transcript definition): A specification-level defect rather than
Impact
A specification-level defect rather than an implementation bug. SPDM 1.4 added OpaqueDataLength and OpaqueData fields to FINISH and FINISH_RSP, but the transcript definitions used to compute the FINISH signature and the verify-data HMACs were never updated to cover them. A literal implementation therefore authenticates a message while leaving part of that message unauthenticated - so an attacker in the path can alter the opaque fields without breaking the signature. This is exactly the class of flaw that undermines device attestation quietly: everything validates, and the validated thing is not what was sent.
Who can reach it
An attacker able to modify SPDM traffic between requester and responder - a PCIe interposer, a compromised switch or retimer in the path, or a malicious intermediary in a disaggregated fabric where SPDM crosses a network rather than a board trace.
What to do
Requires a specification erratum plus updated implementations on both ends, so the fix arrives as vendor firmware updates once DMTF publishes and vendors rebase - expect a long tail and no OS-level patch. Nothing to configure. The operator action today is to know that SPDM 1.4 opaque data is not integrity-protected in affected implementations, and not to build any policy decision on values carried there.
References
Related entries
- Linux x86/mm - broadcast TLB flush with PCID disabled: Booting with nopcid clears the PCID feature but broadcast TLBCVE-2026-64229 · Linux x86/mm - broadcast TLB flush with PCID disabledUnscored
- Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT): The ccp driver initialised SNP from the SNP_COMMIT ioctlCVE-2026-64309 · Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT)Unscored
- Linux iommu/amd - IRQ-unsafe locking in guest domain allocation: An IRQ-unsafe lock taken during AMD IOMMU guest domainCVE-2026-68347 · Linux iommu/amd - IRQ-unsafe locking in guest domain allocationUnscored
- Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload path: Branch Sampling and Last Branch RecordCVE-2026-72325 · Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload pathUnscored
- Linux kernel NFSv4 client: a delayed FREE_STATEID can use a freed nfs_serverCVE-2026-74730 · Linux kernel NFSv4 client (nfs_server lifetime across FREE_STATEID)Unscored
- NVMe/TCP host: a short read is reported to userspace as a complete readCVE-2026-89480 · Linux kernel nvme-tcp host (short-read completion accounting)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.