Database/Firmware, BMC & network fabric
FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requested
Impact
_read_fru_data in libfreeipmi/fru/ipmi-fru.c trusts the length of the FRU data a BMC hands back and overflows a stack buffer when the BMC returns more bytes than were asked for. FRU reads are how fleets build hardware inventory - serial numbers, board and chassis data - so this is exercised at scale by asset-tracking and provisioning automation across every node, including GPU chassis and their fabric hardware. A tampered or hostile BMC anywhere in the fleet gets a memory-corruption primitive against the inventory host that talks to all of them. This is a separate bug from the SEL and Dell OEM overflows in the same release: different subsystem, different trigger condition, though the same fixed version.
Who can reach it
Whoever controls the BMC being inventoried, or can answer for it on the management network. The overflow fires during a normal FRU read; no credentials on the management host are required, but an operator or automation must initiate the read.
What to do
Upgrade FreeIPMI to 1.6.19 or take the distro backport, then restart any long-lived inventory or monitoring process that has libfreeipmi mapped. Package-level update on management hosts only - no node drain, reboot or BMC firmware flash.
References
Related entries
- Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation): An unauthenticated HTTP GET for /PSBlock on port 49152NCVD-2014-001-supermicro-ipmi-bmc-firmware-wpc · Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation)Critical
- Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server'sCVE-2021-21538 · Dell iDRAC9 (Virtual Console / authentication)Critical
- Dell iDRAC9 (VNC server): Unauthenticated access to the iDRAC VNC consoleCVE-2022-24422 · Dell iDRAC9 (VNC server)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCVE-2023-3043 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCVE-2023-37293 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executedCVE-2024-27892 · Arista EOS (OpenConfig gNMI Set authorization)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.