Database/Firmware, BMC & network fabric
Dell OMSA: local heap overflow lets a low-privileged user escalate on the GPU host
Impact
A user with a local shell on a node running OMSA can overflow a heap buffer in the privileged agent and gain full control of the host. On a GPU node this matters wherever workloads get local host access - bare-metal tenancy, HPC login and compute nodes with interactive shells, or any container escape that lands a shell on the host - because OMSA elevates it straight to node compromise including hardware management. This is the local variant; CVE-2026-81477 is a separate remote heap overflow requiring high privilege.
Who can reach it
Local shell on a managed node with any low-privileged account.
What to do
Upgrade OMSA to 11.1.0.3 or later and restart the OMSA services. Nodes that do not need the OMSA agent locally can have it removed instead.
References
Related entries
- AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path): The multi-tenant bare-metal nightmareCVE-2023-34335 · AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path)High
- Linux kernel occ hwmon: truncated OCC poll response is parsed past the valid dataCVE-2026-68340 · Linux kernel occ hwmon driver (IBM POWER OCC poll response parser)High
- openshift-metal3 fakefish: unquoted shell variables in the Redfish shim allow command injectionCVE-2026-71567 · openshift-metal3 fakefish (Redfish-to-BMC shim scripts)High
- Arista EOS: gNMI fails to enforce Pathz policy when a group rule and a user rule cover the same pathCVE-2026-73439 · Arista EOS gNMI server (gNSI Pathz policy enforcement)High
- Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon D: The UEFI settingCVE-2018-3652 · Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon DHigh
- AMI MegaRAC SPx (BMC cryptography / HMAC): The BMC uses inadequate HMAC strength, so an attacker positionedCVE-2023-34337 · AMI MegaRAC SPx (BMC cryptography / HMAC)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.