Back

HIGH

freeipmi: buffer overflows on response messages via ipmi-oem

Published Mar 24, 2026

Description

ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermicro servers," and "ipmi-oem wistron read-proprietary-string - read a proprietary string on Wistron servers."

Affected products

Remediation

Red Hat statement

To exploit this vulnerability, a user needs to execute the `ipmi-oem` program to retrieve information from a compromised or malicious Baseboard Management Controller (BMC) server, limiting the exposure of this flaw. Specifically, the following `ipmi-oem` commands are vulnerable to this issue: - ipmi-oem dell get-last-post-code - ipmi-oem supermicro extra-firmware-info - ipmi-oem wistron read-proprietary-string Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to these reasons, this flaw has been rated with a moderate severity.

Red Hat mitigation

To mitigate this issue, ensure all BMCs and the servers running FreeIPMI are isolated on a dedicated and restricted network environment.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 24, 2026
Updated Jun 3, 2026
Reserved Mar 22, 2026
CISA Vulnrichment
Updated Mar 24, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 24, 2026