GPU VulnDB

Database/Firmware, BMC & network fabric

FreeIPMI ipmi-oem: stack buffer over-read when a BMC returns a short Fujitsu SEL response

CVSS 7.5CVE-2026-85505Firmware, BMC & network fabriccurated

Impact

FreeIPMI is the tooling most fleets script BMC work with, so this runs on the management host that talks to every node's service processor. When a BMC answers the Fujitsu OEM SEL long-text command with a response shorter than expected, ipmi_oem_fujitsu_get_sel_entry_long_text reads past the end of a stack buffer. The rated impact is availability only: the collection tool dies, not the node, so the practical loss is a broken SEL sweep or monitoring run rather than a compromised host. This is a distinct bug from CVE-2026-50031, which affects different versions, so patching for that one does not cover this.

Who can reach it

Whatever answers the IPMI session the operator opens: a malfunctioning or hostile BMC, or anyone positioned to respond on the management VLAN. No authentication against the tool is involved; the operator running ipmi-oem against that target is the trigger.

What to do

Upgrade FreeIPMI to 1.6.19 (source tarball on ftp.gnu.org, or your distribution's backport). This is a command-line tool, so it is a package update in place on management hosts and jump boxes: no daemon to restart, no GPU node downtime.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.