-
Security Bulletin: NVIDIA ConnectX and BlueField – October 2024 (CVE‑2024-0105 and CVE-2024-0106) – 31th Oct 2024
Preface: Nvidia BlueField is a line of data processing units (DPUs) designed and produced by Nvidia. Initially developed by Mellanox Technologies. DOCA is a consistent and essential resource across all existing and future generations of BlueField DPU and SuperNIC products. Background: The NVIDIA cloud-native supercomputing platform leverages the NVIDIA BlueField DPU architecture with high-speed, low-latency.…
-
About btrfs: fix uninitialized pointer free in add_inode_ref() – CVE-2024-50088 (30th Oct 2024)
Preface: The main benefit of a snapshot is that it can be created very rapidly—and frequently—allowing for a quick and straightforward way to recover files or data if something goes wrong. Data can be restored to a specific point in time when it was in a good state. Background: Btrfs is a copy-on-write (COW) file…
-
CVE-2024-10455 Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block (28 Oct 2024)
Preface: µD3TN is a free space-tested software protocol stack for delay-tolerant networks. It runs on POSIX and Linux operating systems and can easily adapt to a variety of challenging networks. The source code is available under a BSD license. AREAS OF APPLICATION : Car-to-X Communication ,Offshore Communication , Maritime Research , Satellite Communication and Reliable…
-
Large solar storms can knock out electronics and affect the power grid. It also vulnerable to Super computer (28th Oct 2024)
Preface: Large solar storms can knock out electronics and affect the power grid. Why? The solar wind disturbs the outer part of the Earth’s magnetic field, which undergoes a complex oscillation. This generates associated electric currents in the near-Earth space environment, which in turn generates additional magnetic field variations — all of which constitute a…
-
On 21st October 2024 Broadcom issued an update to advisory CMSA-2024-0019 stating that they had determined patches released on 17th September 2024 did not fully address CVE-2024-38812 and subsequently have issued new patches. (25-10-2024)
Preface: System-Dependent IDL Preprocessor Variables The following system-dependent preprocessor variables are used in building the IDL compiler. They are all defined in: dce-root-dir/dce/src/rpc/idl/idl_compiler/sysdep[.]h AUTO_HEAP_STACK_THRESHOLD defines an estimate for the maximum size of a stack in a server stub. If the IDL compiler estimates that this amount will be exceeded, objects will be allocated via malloc…
-
About CVE-2024-0127 and CVE-2024-0128 (24-10-2024)
Preface: GPUs are efficient at performing parallel processing tasks, making them ideal for artificial intelligence and machine learning applications. CPUs are better suited for tasks that require single-threaded performance or large amounts of memory access. Background: NVIDIA vGPU software can be used in several ways. Guest VMs use NVIDIA vGPUs in the same manner as…
-
CVE-2024-50311: A denial of service (DoS) vulnerability was found in OpenShift (23rd Oct 2024)
Preface: Typical REST APIs exhibit a few issues that we can solve with GraphQL. One of the most prominent is over fetching, which occurs when a client fetches too much data from the server. When OpenShift Console is fetching a lot of data, it leverages chunked responses introduced in k8s 1.9. Fetching is split into…
-
CVE-2024-49861: bpf (Fix helper writes to read-only maps) – 22 Oct 2024
Preface: BPF is a highly flexible and efficient virtual machine-like construct in the Linux kernel allowing to execute bytecode at various hook points in a safe manner. It is used in a number of Linux kernel subsystems, most prominently networking, tracing and security (e.g. sandboxing). Background: BPF does not define itself by only providing its…
-
AMD’s response to the research paper that their technical details do not demonstrate any new security vulnerabilities in AMD prefetchers. (18 Oct 2024)
Preface: A hardware prefetcher is a data prefetching technique implemented as a hardware component in a processor, aimed at improving performance by fetching data before it is actually needed. Let’s take a closer look at prefetching. And speculate what kind of prefetching will approach this discussion. Background: A research paper titled ‘ShadowLoad: Injecting State into…
-
VMware HCX resolves CVE-2024-38814 vulnerability (18-10-2024)
Preface: T-SQL is widely used in SQL Server environments. For instance, communication between an app and a SQL Server instance involves sending T-SQL statements to the server. Background: VMware HCX streamlines migration, helps rebalance workloads, helps protect data, and optimizes disaster recovery processes for both on-premises data centers and cloud servers. HCX Connector or Cloud…