
...spend a fraction of that on actual customer code bases. ... what's interesting now? 1. Finding new vulnerability smells in well-audited code @hdmoore built a critical exploit in OpenBMC based on the symmetry scanner output (CVE-2026-16140)
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

...spend a fraction of that on actual customer code bases. ... what's interesting now? 1. Finding new vulnerability smells in well-audited code @hdmoore built a critical exploit in OpenBMC based on the symmetry scanner output (CVE-2026-16140)