GPU VulnDB

Database/Firmware, BMC & network fabric

Gigabyte UEFI firmware (SMM, unvalidated flash function pointers): Function pointer structures governing SPI flash

CVE-2025-7028Firmware, BMC & network fabricVU#746790curated

Impact

Function pointer structures governing SPI flash operations are not validated, so an attacker in SMM context can redirect the routines that read, write and erase the platform firmware. This is the worst of the four: it hands the attacker the flash-write primitive directly, meaning a permanent bootkit rather than a runtime compromise.

Who can reach it

Local privileged code on the host.

What to do

Gigabyte BIOS update per board plus reboot. Because the payoff is a flash write, assume any node you believe was compromised needs firmware re-flashed from a known-good image and its integrity independently verified - a BIOS update applied by a compromised system does not prove anything. For high-value nodes, external SPI verification is the only real assurance.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.