Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21088-1

Опубликовано: 18 июн. 2026
Источник: suse-cvrf

Описание

Security update for freeipmi

This update for freeipmi fixes the following issue

  • CVE-2026-50031: denial of service via buffer overflow in ipmi-oem client (bsc#1267605).

Список пакетов

openSUSE Leap 16.0
freeipmi-1.6.15-160000.4.1
freeipmi-bmc-watchdog-1.6.15-160000.4.1
freeipmi-devel-1.6.15-160000.4.1
freeipmi-ipmidetectd-1.6.15-160000.4.1
freeipmi-ipmiseld-1.6.15-160000.4.1
libfreeipmi17-1.6.15-160000.4.1
libipmiconsole2-1.6.15-160000.4.1
libipmidetect0-1.6.15-160000.4.1
libipmimonitoring6-1.6.15-160000.4.1

Описание

ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages.


Затронутые продукты
openSUSE Leap 16.0:freeipmi-1.6.15-160000.4.1
openSUSE Leap 16.0:freeipmi-bmc-watchdog-1.6.15-160000.4.1
openSUSE Leap 16.0:freeipmi-devel-1.6.15-160000.4.1
openSUSE Leap 16.0:freeipmi-ipmidetectd-1.6.15-160000.4.1

Ссылки