Database/Firmware, BMC & network fabric
Cisco NX-OS: crafted IP packets to a VXLAN OAM interface give unauthenticated root code execution
Impact
An unauthenticated attacker who can send IP packets to any IP interface on a Nexus switch with the NGOAM feature enabled can execute arbitrary code as root on the switch, or crash the process and force a reload. On a GPU fleet the Nexus line is usually the east-west leaf/spine carrying tenant traffic and often the VXLAN overlay that separates tenants, so code execution on the switch means control over inter-tenant isolation, and a forced reload drops every node hanging off that leaf mid-job. Cisco split this VXLAN OAM input-validation flaw across two ids with the same description, score and advisory; this entry covers both. CVSS 9.8 with no authentication and no user interaction.
Who can reach it
Anyone who can route an IP packet to any IP interface on an affected switch - no authentication and no credentials needed. Requires the NGOAM feature to be enabled; switches without NGOAM are not affected.
What to do
Upgrade to a fixed NX-OS release per the Cisco advisory; an NX-OS upgrade means a switch reload, so each leaf has to be taken through a maintenance window (or the job rescheduled off it) unless the fabric is dual-homed and can lose one uplink. Where that cannot be scheduled quickly, disabling NGOAM removes the exposure. The record does not name specific fixed versions - check the advisory for the release matrix.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Cisco NX-OS: crafted IP packets to an SRv6 OAM interface give unauthenticated root code executionCVE-2026-76501 · Cisco NX-OS NGOAM (SRv6 OAM packet handling)Critical
- Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API accessCVE-2026-76504 · Cisco Catalyst SD-WAN Manager (API session authentication, URI encoding handling)Critical
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCVE-2026-85504 · FreeIPMI libfreeipmi SEL parser (Fujitsu iRMC OEM long-text records)Critical
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCVE-2026-85506 · FreeIPMI ipmi-oem (Dell get-system-info handlers)Critical
- FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requestedCVE-2026-85509 · FreeIPMI libfreeipmi FRU reader (_read_fru_data)Critical
- Linux RDMA/rtrs-srv: unvalidated usr_len from the wire underflows data_len into an out-of-bounds lengthCVE-2026-97413 · Linux kernel RDMA/rtrs-srv (process_read/process_write usr_len validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.