Database/Firmware, BMC & network fabric
Cisco NX-OS: crafted IP packets to an SRv6 OAM interface give unauthenticated root code execution
Impact
With both NGOAM and SRv6 enabled, an unauthenticated attacker who can send crafted IP packets to an IP interface on the switch gets arbitrary code execution as root, or can crash the process and trigger a reload. This is the SRv6 OAM path rather than the VXLAN one ([[CVE-2026-76485]]) and needs SRv6 configured, so it hits fabrics that use segment routing over IPv6 for the datacenter underlay. Root on a leaf or spine in a GPU fabric means an attacker sits in the path of tenant traffic; a reload stalls every collective crossing that switch.
Who can reach it
Anyone who can reach an IP interface on the switch over the network, unauthenticated. Requires the NGOAM and SRv6 features to both be enabled.
What to do
Upgrade to a fixed NX-OS release listed in the Cisco advisory, which requires reloading the switch and therefore a maintenance window per device. Disabling NGOAM, or SRv6 where it is not needed, removes the exposure in the meantime. The record names no fixed version - take it from the advisory.
References
Related entries
- Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API accessCVE-2026-76504 · Cisco Catalyst SD-WAN Manager (API session authentication, URI encoding handling)Critical
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCVE-2026-85504 · FreeIPMI libfreeipmi SEL parser (Fujitsu iRMC OEM long-text records)Critical
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCVE-2026-85506 · FreeIPMI ipmi-oem (Dell get-system-info handlers)Critical
- FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requestedCVE-2026-85509 · FreeIPMI libfreeipmi FRU reader (_read_fru_data)Critical
- Linux RDMA/rtrs-srv: unvalidated usr_len from the wire underflows data_len into an out-of-bounds lengthCVE-2026-97413 · Linux kernel RDMA/rtrs-srv (process_read/process_write usr_len validation)Critical
- Linux kernel soft-RoCE: integer overflow in MR range check gives a remote peer out-of-bounds kernel accessCVE-2026-98365 · Linux kernel RDMA/rxe (soft-RoCE mr_check_range integer overflow)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.