Database/Firmware, BMC & network fabric
Community / open-source SONiC (sonic-net): Community SONiC — the open-source NOS that a growing share of cost-optimised
Impact
Community SONiC — the open-source NOS that a growing share of cost-optimised GPU-cluster fabrics run on — has essentially no published CVE history. A CPE-based NVD query returns zero records, and the project's own process routes reports privately to its security committee. This is not evidence that SONiC is secure; it is evidence that you have no vulnerability feed for the operating system running your leaf/spine. Every downstream commercial distribution that has been examined (Dell Enterprise SONiC) has produced multiple 9.x-severity findings including authentication bypass, command injection, hard-coded and default credentials — which is what you would expect the shared upstream to look like too. Operators running community SONiC are patching blind.
Who can reach it
Not a specific vulnerability. The exposure is process-level: an operator cannot subscribe to a feed that tells them when their switch OS needs patching, so known-vulnerable images stay in production indefinitely.
What to do
No patch to apply. Practical controls: pin to a distribution that issues advisories (Dell, Edgecore or a vendor-supported build) rather than self-built community images; track the sonic-buildimage git history for security-relevant commits since there is no advisory feed; scan the SONiC container images for known-vulnerable component versions, because most of the real risk is the Debian base and the bundled daemons (lldpd, FRR, redis, the SDK) rather than SONiC-specific code; and keep switch management interfaces on an isolated OOB network on the assumption that you will not learn about the next flaw in time.
References
Related entries
- Rack PDU and UPS management estates as a class (all vendors): PHYSICAL, and the most common real-world findingNCVD-2026-018-rack-pdu-and-ups-management-esta · Rack PDU and UPS management estates as a class (all vendors)Unscored
- Leased colocation facility infrastructure (power, cooling, access control) as a class: Most GPU operators lease spaceNCVD-2026-019-leased-colocation-facility-infra · Leased colocation facility infrastructure (power, cooling, access control) as a classUnscored
- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostNCVD-2026-023-nvme-admin-command-set-firmware · NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the…Unscored
- RAID/HBA controller firmware update path as a classNCVD-2026-025-raid-hba-controller-firmware-upd · RAID/HBA controller firmware update path as a class - Broadcom MegaRAID and LSI 9400/9500/9600 HBAs, Microchip…Unscored
- Leased colocation facility infrastructure (power, cooling, access control) as a class: Most GPU operators lease spaceNCVD-2026-026-leased-colocation-facility-infra · Leased colocation facility infrastructure (power, cooling, access control) as a classUnscored
- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostNCVD-2026-028-nvme-admin-command-set-firmware · NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the…Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.