Database/Firmware, BMC & network fabric

EDK II SecurityPkg (Tcg2Dxe, Tcg2MeasureGptTable): A crafted GPT partition table overflows the heap inside the very
Impact
A crafted GPT partition table overflows the heap inside the very code that is supposed to measure the disk layout into the TPM. Two consequences that matter for a fleet: the attacker gets code execution during boot, and the compromise happens inside the measured-boot machinery itself, so the PCR values that downstream attestation trusts are produced by code the attacker already controls. Remote attestation of the node becomes meaningless while telling you everything is fine.
Who can reach it
Anyone who can present a disk with an attacker-controlled GPT to the node - a tenant who had the box before you and wrote to a local drive, a removable device, or an iSCSI/SAN LUN whose contents the attacker influences. Requires the node to boot with that disk attached.
What to do
OEM BIOS update; the upstream edk2 fix predates public disclosure by over a year, so most current server BIOS lines already carry it - confirm against the OEM release notes for your exact platform generation rather than assuming. Flash + reboot per node. No config workaround inside firmware; operationally, wiping and re-partitioning tenant disks between leases reduces exposure but does not close the bug.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.