Database/Firmware, BMC & network fabric
GNU FreeIPMI ipmi-oem before 1.6.18: Same shape as its predecessor and the same fleet consequence: a hostile BMC
Impact
Same shape as its predecessor and the same fleet consequence: a hostile BMC response corrupts memory in the tool on your management host. The operationally important detail is that this is the second round - an operator who updated to 1.6.17 believing FreeIPMI's OEM response parsing was fixed is still exposed. Treat the ipmi-oem response parser as untrusted code handling untrusted input until proven otherwise, rather than assuming a given release closed the class. A further set of response-message buffer overflows found after the 1.6.17 fix, meaning the first round of hardening did not cover the whole parser.
Who can reach it
Your management tooling querying a BMC that returns crafted responses - a compromised controller, a node brought in from an untrusted source, or an attacker able to interpose on IPMI traffic across the management VLAN.
What to do
Package update to FreeIPMI 1.6.18 or later everywhere ipmi-oem runs. Cheap: distribution package update, no reboot, no firmware. Given that OEM extension parsing has now produced two rounds of overflows, the stronger move for most GPU operators is to stop using ipmi-oem for routine fleet polling at all - vendor-specific OEM IPMI commands are rarely load-bearing, and dropping them removes this parser from your control plane entirely.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): Every time an XDP_TX transmit fails because the XDP sendCVE-2026-53229 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Two CPUs write to the internal control send queue withoutCVE-2026-64210 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/infiniband/hw/mlx5): When on-demand-paging translation-table population fails, the UMR pathCVE-2026-74396 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Dell OMSA: unauthenticated path traversal exposes arbitrary files from the managed nodeCVE-2026-81481 · Dell OpenManage Server Administrator (path traversal, unauthenticated)High
- FreeIPMI ipmi-oem: stack buffer over-read when a BMC returns a short Fujitsu SEL responseCVE-2026-85505 · FreeIPMI ipmi-oem (Fujitsu get-sel-entry-long-text handler)High
- Linux mlxsw: PTP garbage collector calls napi_gro_receive outside NAPI context, corrupting the GRO listCVE-2026-98050 · Linux kernel mlxsw spectrum_ptp (PTP garbage collector calling napi_gro_receive)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.