GPU VulnDB

Database/Firmware, BMC & network fabric

FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requested

CVSS 9.8CVE-2026-85509Firmware, BMC & network fabriccurated

Impact

_read_fru_data in libfreeipmi/fru/ipmi-fru.c trusts the length of the FRU data a BMC hands back and overflows a stack buffer when the BMC returns more bytes than were asked for. FRU reads are how fleets build hardware inventory - serial numbers, board and chassis data - so this is exercised at scale by asset-tracking and provisioning automation across every node, including GPU chassis and their fabric hardware. A tampered or hostile BMC anywhere in the fleet gets a memory-corruption primitive against the inventory host that talks to all of them. This is a separate bug from the SEL and Dell OEM overflows in the same release: different subsystem, different trigger condition, though the same fixed version.

Who can reach it

Whoever controls the BMC being inventoried, or can answer for it on the management network. The overflow fires during a normal FRU read; no credentials on the management host are required, but an operator or automation must initiate the read.

What to do

Upgrade FreeIPMI to 1.6.19 or take the distro backport, then restart any long-lived inventory or monitoring process that has libfreeipmi mapped. Package-level update on management hosts only - no node drain, reboot or BMC firmware flash.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.