Database/Firmware, BMC & network fabric
Dell iDRAC9 / iDRAC10 (memory erase, data remanence): Data survives an iDRAC memory erase and stays readable
Impact
Data survives an iDRAC memory erase and stays readable afterwards. The CVSS is low, but the operational meaning for a bare-metal GPU cloud is not: the erase step in your node-reprovisioning pipeline does not actually erase, so a low-privilege user on the next tenancy can read remnants left by the previous one. This is exactly the cross-tenant handoff failure that bare-metal operators promise does not happen, and it fails quietly - the wipe reports success. Affects both the iDRAC9 and iDRAC10 generations.
Who can reach it
A low-privilege account with remote access to the iDRAC - which on a bare-metal cloud can be the next tenant, if your product hands tenants any BMC-adjacent access at all, or anyone reaching the management VLAN.
What to do
Flash iDRAC9 to 7.20.30.50 or iDRAC10 to 1.20.60.50 or later. Out-of-band, per-node, no host reboot and no job drain. Beyond the flash, treat this as a pipeline bug rather than a node bug: if your reprovisioning runbook relies on the iDRAC erase as the cross-tenant boundary, add an independent verification step, and consider re-checking nodes that were recycled between tenants on unpatched firmware.
References
Related entries
- IBM OpenBMC: host can crash the BMC firmware management service or read BMC internal memoryCVE-2026-18857 · IBM OpenBMC (BMC firmware management interface)Low
- AMD SEV guest VMs - TLB flush after VMCB creation sequence: The CPU may fail to flush the TLB after a particularCVE-2021-26342 · AMD SEV guest VMs - TLB flush after VMCB creation sequenceLow
- AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): A use-after-free inCVE-2023-20519 · AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002)Low
- Intel TDX firmware (PRNG seeding): A predictable seed in the TDX firmware's pseudo-random number generator. PredictableCVE-2025-20613 · Intel TDX firmware (PRNG seeding)Low
- AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptionsCVE-2023-20573 · AMD SEV-SNP - debug exception delivery to guestsLow
- AMD CPU microcode - RDRAND entropy after patch load: Incomplete cleanup after loading a microcode patch degrades theCVE-2024-21977 · AMD CPU microcode - RDRAND entropy after patch loadLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.