freeipmi: buffer overflows on response messages via ipmi-oem
Published Mar 24, 2026
8.8
HIGHCVSS 3.1
EPSS 0.40%
Description
ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermicro servers," and "ipmi-oem wistron read-proprietary-string - read a proprietary string on Wistron servers."
Affected products
-
- Version 0.7.12StatusaffectedConstraints<1.6.17
- Version
No data.
No data.
Red Hat Enterprise Linux 10
freeipmi-0:1.6.17-1.el10_1
Fixed · RHSA-2026:13515
Red Hat Enterprise Linux 10
freeipmi-0:1.6.17-1.el10_2
Fixed · RHSA-2026:19053
Red Hat Enterprise Linux 10.0 Extended Update Support
freeipmi-0:1.6.14-4.el10_0.1
Fixed · RHSA-2026:39007
Red Hat Enterprise Linux 7 Extended Lifecycle Support
freeipmi-0:1.5.7-3.el7_9.1
Fixed · RHSA-2026:48826
Red Hat Enterprise Linux 8
freeipmi-0:1.6.17-1.el8_10
Fixed · RHSA-2026:20579
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
freeipmi-0:1.6.6-1.el8_4.1
Fixed · RHSA-2026:50729
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
freeipmi-0:1.6.6-1.el8_4.1
Fixed · RHSA-2026:50729
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
freeipmi-0:1.6.8-1.el8_6.1
Fixed · RHSA-2026:50772
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
freeipmi-0:1.6.8-1.el8_6.1
Fixed · RHSA-2026:50772
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
freeipmi-0:1.6.8-1.el8_8.1
Fixed · RHSA-2026:50769
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
freeipmi-0:1.6.8-1.el8_8.1
Fixed · RHSA-2026:50769
Red Hat Enterprise Linux 9
freeipmi-0:1.6.17-1.el9_7
Fixed · RHSA-2026:14819
Red Hat Enterprise Linux 9
freeipmi-0:1.6.17-1.el9_8
Fixed · RHSA-2026:19208
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
freeipmi-0:1.6.14-2.el9_2.1
Fixed · RHSA-2026:39010
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
freeipmi-0:1.6.14-2.el9_4.1
Fixed · RHSA-2026:39008
Red Hat Enterprise Linux 9.6 Extended Update Support
freeipmi-0:1.6.14-2.el9_6.1
Fixed · RHSA-2026:39006
Red Hat Enterprise Linux 6
freeipmi
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | freeipmi-0:1.6.17-1.el10_1 | Fixed | RHSA-2026:13515 |
| Red Hat Enterprise Linux 10 | freeipmi-0:1.6.17-1.el10_2 | Fixed | RHSA-2026:19053 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | freeipmi-0:1.6.14-4.el10_0.1 | Fixed | RHSA-2026:39007 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | freeipmi-0:1.5.7-3.el7_9.1 | Fixed | RHSA-2026:48826 |
| Red Hat Enterprise Linux 8 | freeipmi-0:1.6.17-1.el8_10 | Fixed | RHSA-2026:20579 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | freeipmi-0:1.6.6-1.el8_4.1 | Fixed | RHSA-2026:50729 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | freeipmi-0:1.6.6-1.el8_4.1 | Fixed | RHSA-2026:50729 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | freeipmi-0:1.6.8-1.el8_6.1 | Fixed | RHSA-2026:50772 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | freeipmi-0:1.6.8-1.el8_6.1 | Fixed | RHSA-2026:50772 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | freeipmi-0:1.6.8-1.el8_8.1 | Fixed | RHSA-2026:50769 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | freeipmi-0:1.6.8-1.el8_8.1 | Fixed | RHSA-2026:50769 |
| Red Hat Enterprise Linux 9 | freeipmi-0:1.6.17-1.el9_7 | Fixed | RHSA-2026:14819 |
| Red Hat Enterprise Linux 9 | freeipmi-0:1.6.17-1.el9_8 | Fixed | RHSA-2026:19208 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | freeipmi-0:1.6.14-2.el9_2.1 | Fixed | RHSA-2026:39010 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | freeipmi-0:1.6.14-2.el9_4.1 | Fixed | RHSA-2026:39008 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | freeipmi-0:1.6.14-2.el9_6.1 | Fixed | RHSA-2026:39006 |
| Red Hat Enterprise Linux 6 | freeipmi | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this vulnerability, a user needs to execute the `ipmi-oem` program to retrieve information from a compromised or malicious Baseboard Management Controller (BMC) server, limiting the exposure of this flaw. Specifically, the following `ipmi-oem` commands are vulnerable to this issue: - ipmi-oem dell get-last-post-code - ipmi-oem supermicro extra-firmware-info - ipmi-oem wistron read-proprietary-string Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to these reasons, this flaw has been rated with a moderate severity.
Red Hat mitigation
To mitigate this issue, ensure all BMCs and the servers running FreeIPMI are isolated on a dedicated and restricted network environment.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Mar 24, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.40% (0.00403) | 32.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.38% (0.00382) | 29.75th | v5 (v2026.06.15) |
| Mar 25, 2026 | 0.04% (0.00042) | 12.62th | v4 (v2025.03.14) |
References (9)
- http://www.openwall.com/lists/oss-security/2026/06/03/1
- https://access.redhat.com/security/cve/CVE-2026-33554 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2450778 Issue Tracking
- https://ftp.gnu.org/gnu/freeipmi/
- https://nvd.nist.gov/vuln/detail/CVE-2026-33554
- https://savannah.gnu.org/bugs/?68140
- https://savannah.gnu.org/bugs/?68141
- https://savannah.gnu.org/bugs/?68142
- https://www.cve.org/CVERecord?id=CVE-2026-33554
Change history (0)
No recorded changes yet.