Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS (SmmComputrace DXE module): The SmmComputrace DXE module leaks stack and global memory to a local
Impact
The SmmComputrace DXE module leaks stack and global memory to a local attacker, giving up the addresses and secrets needed to defeat firmware memory protections and escalate to arbitrary code execution and OS security bypass. Computrace is the anti-theft persistence module - it exists specifically to survive OS reinstall, so a bug in it lands in code designed for durability. Most datacenter operators do not use Computrace at all and do not realise the module is compiled into their BIOS anyway.
Who can reach it
Local, low privileges, no interaction. Any code on the host OS can start reading. On a bare-metal GPU rental the tenant qualifies without doing anything unusual.
What to do
BIOS update from your server vendor with the fixed AptioV build - firmware flash plus host reboot per node, vendor-gated, and AMI names only 'AptioV' as the fix version so you have to confirm the specific BIOS release with your OEM. The useful config-only step here is subtractive: check whether Computrace is enabled in BIOS setup on your fleet and disable it, since datacenter operators almost never need it and it removes the attack surface with a setup change plus one reboot rather than a firmware flash campaign.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.