important · Firmware — FreeIPMI
A malicious BMC can overwrite a FreeIPMI management client’s stack during a routine FRU read.
Affects
FreeIPMI management clients on Linux and Unix hosts used to query server baseboard-management controllers.
A compromised BMC returns more FRU bytes than requested, and the client copies them beyond a fixed-size stack buffer when an administrator reads inventory.
Detail and 3 sources
Controlled execution remains unproved; FreeIPMI 1.6.19’s announcement says it fixes stack overflows caused by nonconforming BMC responses.
Chain to watch
Compromise a BMC queried by an affected client→↓Return an oversized FRU response→↓Convert the stack overwrite into controlled instruction flow→↓Arbitrary code execution and the affected client process identity remain unverified.
Unverified chainReproduce a benign control-flow proof against a pre-1.6.19 client and record its hardening and process identity.