Database/Firmware, BMC & network fabric

Linux kernel occ hwmon: truncated OCC poll response is parsed past the valid data
Impact
The OCC poll response parser walks a counted list of sensor blocks using the static backing-array capacity as its boundary, but only data_length bytes of a transport response are actually current and valid. A truncated response therefore lets the parser consume a block header or a block extent that lies outside the response, an out-of-bounds read; the record's vector also carries a high availability impact. This driver is how IBM POWER systems surface processor power and thermal telemetry from the On-Chip Controller to the management stack. On a GPU or HPC node that telemetry is the input to power capping and cooling decisions, so the operational consequence of a bad parse is losing or corrupting the power/thermal picture for a machine, not a tenant-visible compromise.
Who can reach it
Not network-facing and not reachable by a tenant. It requires the OCC transport (FSI/SBE or I2C, depending on platform) to hand back a truncated or malformed poll response — a misbehaving or compromised OCC, or transport-level errors. No authentication boundary is crossed.
What to do
The record is a set of kernel commits, not a platform advisory: it does not say which service-processor or system firmware releases carry the fix. Track your platform vendor's firmware release notes and take the image that includes it. In practice this lands as a service-processor/BMC firmware update, which interrupts out-of-band management while it applies; confirm against your vendor's procedure whether a host outage is required before scheduling.
References
Related entries
- openshift-metal3 fakefish: unquoted shell variables in the Redfish shim allow command injectionCVE-2026-71567 · openshift-metal3 fakefish (Redfish-to-BMC shim scripts)High
- Arista EOS: gNMI fails to enforce Pathz policy when a group rule and a user rule cover the same pathCVE-2026-73439 · Arista EOS gNMI server (gNSI Pathz policy enforcement)High
- Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon D: The UEFI settingCVE-2018-3652 · Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon DHigh
- AMI MegaRAC SPx (BMC cryptography / HMAC): The BMC uses inadequate HMAC strength, so an attacker positionedCVE-2023-34337 · AMI MegaRAC SPx (BMC cryptography / HMAC)High
- Dell iDRAC9 (IPMI 2.0 over LAN): iDRAC9 generates predictable IPMI 2.0 session IDs, so an attacker can hijack somebodyCVE-2024-25943 · Dell iDRAC9 (IPMI 2.0 over LAN)High
- IBM Power Systems Firmware: unauthenticated ASMI web request crashes the service-processor interfaceCVE-2026-16828 · IBM Power Systems Firmware ASMI web interfaceHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.