Описание
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
A stack-based out-of-bounds read vulnerability was found in the FreeIPMI ipmi-oem utility. When processing an abnormally short response from a Baseboard Management Controller (BMC), the application over-reads the buffer. A malicious BMC could exploit this to crash the client application (Denial of Service) or potentially leak stack memory. Red Hat compiler safeguards further restrict the impact primarily to a process crash.
Отчет
A flaw in the ipmi_oem_fujitsu_get_sel_entry_long_text function of FreeIPMI allows an out-of-bounds read. If a BMC returns an unexpectedly truncated System Event Log (SEL) response, the client fails to validate the data length before reading. This causes the application to read past the allocated stack buffer boundaries, leading to a crash or potential memory disclosure.
Меры по смягчению последствий
Restrict IPMI and BMC access to a dedicated, trusted management network so ipmi-oem cannot reach untrusted or compromised Fujitsu controllers. Until a fixed freeipmi package is installed, do not run ipmi-oem fujitsu get-sel-entry-long-text against untrusted BMCs. If that OEM SEL long-text query is not required, do not use ipmi-oem against remote management controllers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 6 | freeipmi | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 8 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 9 | freeipmi | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read ...
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
EPSS
6.5 Medium
CVSS3