Database/Control plane, storage & DevOps

DMTF libspdm (GET_MEASUREMENT_EXTENSION_LOG offset/length wrap): Wrapping addition of the Offset and Length fields
Impact
Wrapping addition of the Offset and Length fields in GET_MEASUREMENT_EXTENSION_LOG lets a requester read memory outside the measurement log from a libspdm responder. The attacker is the host or fabric peer asking a device for its measurements, and what it gets back is device firmware memory - which is where attestation keys and secrets live. No CVE was assigned, so this will not appear in NVD, OSV or any scanner your fleet runs.
Who can reach it
Any SPDM requester that can reach an affected responder with MEL_CAP and CHUNK_CAP set - in practice the host talking to its own accelerators or NICs, so host-side root on a bare-metal node is enough.
What to do
libspdm update embedded in device or platform firmware, plus - importantly - integrator hygiene: the bug only bites when the integrator's libspdm_copy_mem() has its assertions compiled out, which is a build-configuration decision your device vendor made and you cannot see. There is no config mitigation and no way to detect affected devices from the outside. Ask vendors directly for their libspdm version and build flags as part of hardware acceptance; that question is the only real control here.
References
Related entries
- Linux Safe RET SRSO mitigation on AMD Zen 1-Zen 4 - interrupt-induced weakening: An attacker executing code on theNCVD-2026-001-linux-safe-ret-srso-mitigation-o · Linux Safe RET SRSO mitigation on AMD Zen 1-Zen 4 - interrupt-induced weakeningUnscored
- DMTF libspdm (cryptlib_mbedtls CSR generation, stack overflow): An over-long Common Name in a GET_CSR request writesNCVD-2026-002-dmtf-libspdm-cryptlib-mbedtls-cs · DMTF libspdm (cryptlib_mbedtls CSR generation, stack overflow)Unscored
- AMD - REP-string execution unit scheduler contention side channel: A newer variant of the SQUIP scheduler-contentionNCVD-2026-003-amd-rep-string-execution-unit-sc · AMD - REP-string execution unit scheduler contention side channelUnscored
- Das U-Boot (FIT image signature verification): Binarly disclosed a cluster of flaws in U-Boot's FIT image handlingNCVD-2026-005-das-u-boot-fit-image-signature-v · Das U-Boot (FIT image signature verification)Unscored
- WEKA Data Platform and VAST Data (published-advisory coverage): Neither WEKA nor VAST DataNCVD-2026-014-weka-data-platform-and-vast-data · WEKA Data Platform and VAST Data (published-advisory coverage)Unscored
- BACnet / BACnet IP as a protocol (facility control plane): BACnet has no authentication, no integrity protection and noNCVD-2026-024-bacnet-bacnet-ip-as-a-protocol-f · BACnet / BACnet IP as a protocol (facility control plane)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.