freeipmi-1.6.18-1.el9_8
エラータID: AXSA:2026-1471:04
The freeipmi packages contain an Intelligent Platform Management Interface (IPMI) remote console and system management software based on the IPMI specification.
Security Fix(es):
* freeipmi: FreeIPMI: Denial of service via buffer overflow in ipmi-oem client (CVE-2026-50031)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-50031
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages.
Update packages.
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages.
N/A
SRPMS
- freeipmi-1.6.18-1.el9_8.src.rpm
MD5: d07f168280ac9d5f62280d49c61180c3
SHA-256: 75cb3b48443e1255aabc4b356cb84889e5ec63ad7acdb214495f0e50691c071e
Size: 3.30 MB
Asianux Server 9 for x86_64
- freeipmi-1.6.18-1.el9_8.i686.rpm
MD5: 2f897fbcee932af5faa74363b748f794
SHA-256: 42d9c3658f335506911f09bdddcd6d13e6313b20c8250306619857fcf7319c55
Size: 1.97 MB - freeipmi-1.6.18-1.el9_8.x86_64.rpm
MD5: d40c0e74dd77b8f0bb8de6dc98334e8a
SHA-256: 6ab95b4fd478ae6f1441d4e3b205089283c20b8080c3b7916e843fee5c1b83d5
Size: 2.05 MB - freeipmi-bmc-watchdog-1.6.18-1.el9_8.x86_64.rpm
MD5: ca67139ccf5ecddc63b59559193f9700
SHA-256: 76c8e2359c3ab5ed849354815e099e7dc183fd288f1d370e39358bf7fdea6908
Size: 62.23 kB - freeipmi-devel-1.6.18-1.el9_8.i686.rpm
MD5: f07889b74a1c929ac694abc28f85714a
SHA-256: 289bfcd4da7dbcf766044aa461b3d8744355a0241dd7c17cd57967124db209fc
Size: 291.06 kB - freeipmi-devel-1.6.18-1.el9_8.x86_64.rpm
MD5: db0b2a36c4ca0445b5c94fe6a97cec0d
SHA-256: 473b252fcba928d3f5367000ae6290e29b0df68d6a94cc15c080f23fd558006e
Size: 291.11 kB - freeipmi-ipmidetectd-1.6.18-1.el9_8.x86_64.rpm
MD5: 94936293a0b530a682e9f9dc9f38bca9
SHA-256: 3507421b1ad31ecbf18187e15a5f4f71a38df52c5aeb62de225c9e5565194d52
Size: 29.49 kB - freeipmi-ipmiseld-1.6.18-1.el9_8.x86_64.rpm
MD5: bb9c7ddb51cd26c3f44f624fd8e5fae3
SHA-256: 9ab842e105468214aa0d3c454fbc0500ea43b58a1109f3680e7ee5baf5792d9f
Size: 82.83 kB