Database/Firmware, BMC & network fabric

U-Boot: malicious NFS server overflows the boot-time NFS read buffer
Impact
A host that netboots over NFS trusts the reply lengths the server sends. Signed integer handling in nfs_read_reply() lets a malicious or impersonating NFS server bypass the length check and write far past the destination buffer, crashing the bootloader or corrupting pre-OS memory before any OS integrity control exists. On fleets where ARM control nodes, DPUs and diskless compute nodes PXE/NFS-boot from a provisioning network, whoever can answer as the NFS server - or sit in the path - influences code execution in the boot environment. Recovery is a console-level operation, not a reboot.
Who can reach it
Network position: whoever operates or can spoof the NFS server the node boots from, on the provisioning/management network. No authentication of the server is involved - U-Boot's NFS client trusts the reply.
What to do
Update U-Boot to 2026.10-rc5 or later, or backport commit 0bbf09859658. That means building and flashing the bootloader on each affected board with the node out of service, so it is a scheduled maintenance item per node, not a rolling restart. Until then, keep the NFS boot server on an isolated provisioning VLAN and prefer boot paths that do not use U-Boot's NFS client.
References
Related entries
- U-Boot: crafted NFS READLINK reply corrupts memory in the bootloaderCVE-2026-74221 · U-Boot net/nfs-common.c (nfs_readlink_reply symlink length)High
- IBM OpenBMC: ReadOnly BMC account can grant itself administrator privilegesCVE-2026-7868 · IBM OpenBMC (Power S1122/S1124 service processor firmware, ReadOnly role)High
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-006-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-012-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processes: NeVerMore showed that an unprivilegedNCVD-2022-001-infiniband-roce-local-rnic-kerne · InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processesHigh
- AMD Secure Processor - TEE parameter handling: A privileged attacker can hand an arbitrary memory value to functionsCVE-2023-20514 · AMD Secure Processor - TEE parameter handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.