Database/Control plane, storage & DevOps

DMTF libspdm (cryptlib_mbedtls CSR generation, stack overflow): An over-long Common Name in a GET_CSR request writes
Impact
An over-long Common Name in a GET_CSR request writes past a stack array inside the responder, corrupting stack data and opening the door to code execution in the device's root-of-trust firmware. The responder here is the thing that is supposed to prove the device is trustworthy, so a compromise at this point does not just break one device - it makes that device's attestation statements attacker-authored. No CVE assigned, so scanners will not flag it.
Who can reach it
Any SPDM requester able to send GET_CSR to a responder that supports CSR_CAP and builds on the mbedTLS crypt backend. On a server that is the host, so local root on a bare-metal node reaches it.
What to do
libspdm update, delivered as device or platform firmware - per-node flash with vendor rebase lag, no package path, no config toggle. Where a device exposes CSR generation you do not use, ask the vendor whether CSR_CAP can be disabled in their build; turning off an unused capability is the only lever an operator has short of the firmware update.
References
Related entries
- AMD - REP-string execution unit scheduler contention side channel: A newer variant of the SQUIP scheduler-contentionNCVD-2026-003-amd-rep-string-execution-unit-sc · AMD - REP-string execution unit scheduler contention side channelUnscored
- Das U-Boot (FIT image signature verification): Binarly disclosed a cluster of flaws in U-Boot's FIT image handlingNCVD-2026-005-das-u-boot-fit-image-signature-v · Das U-Boot (FIT image signature verification)Unscored
- WEKA Data Platform and VAST Data (published-advisory coverage): Neither WEKA nor VAST DataNCVD-2026-014-weka-data-platform-and-vast-data · WEKA Data Platform and VAST Data (published-advisory coverage)Unscored
- BACnet / BACnet IP as a protocol (facility control plane): BACnet has no authentication, no integrity protection and noNCVD-2026-024-bacnet-bacnet-ip-as-a-protocol-f · BACnet / BACnet IP as a protocol (facility control plane)Unscored
- NVMe-oF fabric authentication as deployed - host NQN allowlisting on Linux nvmet, SPDK and most storage appliancesNCVD-2026-024-nvme-of-fabric-authentication-as · NVMe-oF fabric authentication as deployed - host NQN allowlisting on Linux nvmet, SPDK and most storage appliancesUnscored
- Landlord-owned facility control network in a leased colo or wholesale hall (governance gap): Almost every neocloudNCVD-2026-025-landlord-owned-facility-control · Landlord-owned facility control network in a leased colo or wholesale hall (governance gap)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.