Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 before 10.6.1.3: session fixation lets a remote unauthenticated attacker steal a session
Impact
Session fixation in OS10's management interface lets a remote attacker with no credentials end up in possession of an administrator's session, which Dell scores 9.8 with full confidentiality, integrity and availability loss. That is effective switch administration: reading the running configuration, changing VLANs and ACLs, or disrupting the fabric. On a GPU deployment the OS10 switches are the underlay for east-west and storage traffic, and the management interface usually sits on the same management VLAN as BMCs, so an attacker who reaches that VLAN can pivot from a stolen web session to reconfiguring the network under running tenants. The record does not describe the exact fixation mechanism.
Who can reach it
Remote and unauthenticated, against the OS10 management interface - in practice anyone who can reach the management VLAN, plus an administrator session to ride.
What to do
Upgrade OS10 to 10.6.1.3 or later per Dell advisory DSA-2026-343; an OS10 upgrade reloads the switch, so schedule it with the affected racks drained or routed through their redundant uplink. Until then keep the management interface off any network a tenant or user workload can reach and restrict it to a jump host.
References
Related entries
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: The siw receive path decodesCVE-2026-64102 · Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.c: Siw places inbound Read Response segmentsCVE-2026-64268 · Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.c: Nvmet_rdma_use_inline_sg() accepted any host-controlledCVE-2026-72129 · Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.cCritical
- Linux kernel (drivers/infiniband/hw/irdma): The driver signalled completion of control-plane requests through anCVE-2026-72494 · Linux kernel (drivers/infiniband/hw/irdma)Critical
- Linux bnxt_en driver (XDP head-grow underflow): Head underflow when an XDP program grows the packet head on a BroadcomCVE-2026-74269 · Linux bnxt_en driver (XDP head-grow underflow)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.