Database/Firmware, BMC & network fabric
FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responses
Impact
_ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi overflows a stack buffer when a Fujitsu iRMC returns a malformed long-text system event log response. SEL collection is the routine, often automated, path on a fleet - ipmi-sel runs from monitoring and from failure triage on nodes that just fell over - so the code sits in a library that management hosts point at every BMC they own. A BMC that has already been compromised, or an attacker who can answer for one on the management network, can turn a log-collection run into memory corruption on the collector. Distinct from the Dell OEM overflows fixed in the same release: different subsystem, different parser, different trigger.
Who can reach it
Whoever controls the responses of the BMC whose SEL is being read - a compromised Fujitsu iRMC, or an attacker positioned on the management VLAN able to forge IPMI responses. Requires that SEL reading actually be performed against that endpoint; no authentication to the management host is needed.
What to do
Upgrade FreeIPMI to 1.6.19 or take the distro backport. It is a library and CLI package update on management and monitoring hosts - restart whatever long-lived collector links libfreeipmi, but no node drain, reboot or firmware flash. If any monitoring daemon on the management host loads it in-process, that process needs restarting to pick up the new library.
References
Related entries
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCVE-2026-85506 · FreeIPMI ipmi-oem (Dell get-system-info handlers)Critical
- FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requestedCVE-2026-85509 · FreeIPMI libfreeipmi FRU reader (_read_fru_data)Critical
- Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation): An unauthenticated HTTP GET for /PSBlock on port 49152NCVD-2014-001-supermicro-ipmi-bmc-firmware-wpc · Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation)Critical
- Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server'sCVE-2021-21538 · Dell iDRAC9 (Virtual Console / authentication)Critical
- Dell iDRAC9 (VNC server): Unauthenticated access to the iDRAC VNC consoleCVE-2022-24422 · Dell iDRAC9 (VNC server)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCVE-2023-3043 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.