Database/Firmware, BMC & network fabric

U-Boot: crafted NFS READLINK reply corrupts memory in the bootloader
Impact
nfs_readlink_reply() accepts negative or oversized symlink lengths from the NFS server and copies on that basis, corrupting bootloader memory and crashing the boot. This is a separate code path and a separate fix from the READ-reply overflow (CVE-2026-74220), and a node can be reachable through either. For diskless GPU or ARM control nodes that mount their boot tree over NFS, a hostile or spoofed server turns every boot attempt into a failed boot that needs console access to diagnose.
Who can reach it
Network position: the NFS server the node boots from, or anyone able to impersonate it on the provisioning network. No credentials needed - the client does not authenticate reply contents.
What to do
Update U-Boot to 2026.10-rc5 or later, or backport commit 1c0aff3a5fbf. Bootloader replacement means flashing each board with the node out of service. Apply it together with the READ-reply fix so a node is only taken down once. Interim mitigation is network isolation of the boot server.
References
Related entries
- IBM OpenBMC: ReadOnly BMC account can grant itself administrator privilegesCVE-2026-7868 · IBM OpenBMC (Power S1122/S1124 service processor firmware, ReadOnly role)High
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-006-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-012-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processes: NeVerMore showed that an unprivilegedNCVD-2022-001-infiniband-roce-local-rnic-kerne · InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processesHigh
- AMD Secure Processor - TEE parameter handling: A privileged attacker can hand an arbitrary memory value to functionsCVE-2023-20514 · AMD Secure Processor - TEE parameter handlingHigh
- UEFI firmware SMM modules in Intel reference platform firmware (SMM handler, FlashUcAcmSmm, ImcErrorHandler, WheaERSTCVE-2025-20105 · UEFI firmware SMM modules in Intel reference platform firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.