Skip to finding
important · Firmware — FreeIPMI

A malicious BMC can overwrite a FreeIPMI management client’s stack during a routine FRU read.

Affects

FreeIPMI management clients on Linux and Unix hosts used to query server baseboard-management controllers.

A compromised BMC returns more FRU bytes than requested, and the client copies them beyond a fixed-size stack buffer when an administrator reads inventory.

Detail and 3 sources

Controlled execution remains unproved; FreeIPMI 1.6.19’s announcement says it fixes stack overflows caused by nonconforming BMC responses.

Chain to watch
Compromise a BMC queried by an affected client→↓Return an oversized FRU response→↓Convert the stack overwrite into controlled instruction flow→↓Arbitrary code execution and the affected client process identity remain unverified.
Unverified chainReproduce a benign control-flow proof against a pre-1.6.19 client and record its hardening and process identity.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026