freeipmi-1.6.17-1.el8_10
エラータID: AXSA:2026-742:02
リリース日:
2026/06/01 Monday - 19:43
題名:
freeipmi-1.6.17-1.el8_10
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- FreeIPMI の ipmi-oem コマンドには、バッファオーバーフロー
の問題があるため、リモートの攻撃者により、データ破壊、および
サービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2026-33554)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-33554
ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermicro servers," and "ipmi-oem wistron read-proprietary-string - read a proprietary string on Wistron servers."
ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermicro servers," and "ipmi-oem wistron read-proprietary-string - read a proprietary string on Wistron servers."
追加情報:
N/A
ダウンロード:
SRPMS
- freeipmi-1.6.17-1.el8_10.src.rpm
MD5: be9dcc48aaec002757f66197ec97114f
SHA-256: 8101fd09a706dd4f896c539085b04ec9e129981432b6f1603da199ddf1a0996c
Size: 3.31 MB
Asianux Server 8 for x86_64
- freeipmi-1.6.17-1.el8_10.i686.rpm
MD5: b93f2ce9d1d59d904727bd783c31d991
SHA-256: 12f0540869212706ebcd6bfc3e3bde781e5d95e54358056ff4fe5e61a59b628b
Size: 2.04 MB - freeipmi-1.6.17-1.el8_10.x86_64.rpm
MD5: a64db2848d3c9f42938418a3743e4ffe
SHA-256: 3e5d7651d854bfcf940ed687fe72620edf6d89150849119bb7676af8857a9bfe
Size: 2.09 MB - freeipmi-bmc-watchdog-1.6.17-1.el8_10.x86_64.rpm
MD5: baa94251a4c206f6569f7166eb7b2743
SHA-256: 8adfc1209471318f2c08c939aabc6b7c42251259441b7066652674aee68f2344
Size: 82.98 kB - freeipmi-devel-1.6.17-1.el8_10.i686.rpm
MD5: 7d06672dc4d909be14a6e50a2561c605
SHA-256: b29c24a4ea4d0db177aa09ff24d3e746f0721365d19abf71f472197772b166e6
Size: 267.19 kB - freeipmi-devel-1.6.17-1.el8_10.x86_64.rpm
MD5: 8e556ebcfeacc850104e1f81e95c2135
SHA-256: d302d2c8633177c4000c5daaf13fad16c782f207a70731ad6e76307516d67955
Size: 267.16 kB - freeipmi-ipmidetectd-1.6.17-1.el8_10.x86_64.rpm
MD5: ab7e506804adce3457db9fb6a150008f
SHA-256: be8d9f2e0b3db7aba4ef206b24515ba13ad112321dd04a0f78f143fbdb32e0d6
Size: 58.72 kB - freeipmi-ipmiseld-1.6.17-1.el8_10.x86_64.rpm
MD5: ab54b540bc1a3663265066ed1e9e34c4
SHA-256: b9a4aaa03ceacb15b5dbf33185b492332c4c1be40f807f680c0eeb4cbc5ddf25
Size: 124.45 kB