Executive brief
FreeIPMI is a suite of tools for IPMI-based system management, commonly used to monitor and control servers remotely. A vulnerability in the ipmi-oem tool allows a malicious or compromised BMC (baseboard management controller) to trigger a stack-based buffer over-read when processing certain system event log entries, potentially exposing sensitive information or causing a denial of service.
Technical details
The vulnerability is a stack-based buffer over-read in the ipmi_oem_fujitsu_get_sel_entry_long_text function within ipmi-oem/ipmi-oem-fujitsu.c. It occurs when a BMC provides a response shorter than expected while parsing Fujitsu-specific SEL (System Event Log) entries. The vulnerable code does not properly validate response length before dereferencing memory on the stack. An attacker with access to a BMC or the ability to intercept IPMI communication can trigger this condition. The impact includes information disclosure or denial of service. FreeIPMI version 1.6.19 and later contain a fix.
Affected products
- GNU FreeIPMI before 1.6.19
Timeline
- 2026-09-04: disclosed
- 2026-08-27: patched: FreeIPMI 1.6.19 released