AI analysis
FreeIPMI before 1.6.19 contains a stack-based buffer overflow (CWE-121) in the _read_fru_data function in libfreeipmi/fru/ipmi-fru.c, the code that parses Field Replaceable Unit (FRU) inventory data read from a server's BMC. The flaw is triggered when a BMC returns more bytes than were requested in the FRU read, overrunning a fixed-size stack buffer, so exploitation requires control of the BMC side, e.g. a compromised or malicious BMC or an attacker in the path of an out-of-band (IPMI LAN) session. A successful attack can crash the FreeIPMI tool or monitoring service and, as a stack overflow, may allow arbitrary code execution with the privileges of the process, which typically runs privileged for in-band hardware monitoring; CVSS 3.1 rates it 9.8 (Critical). Any deployment running FreeIPMI prior to 1.6.19 is affected, including installations from major Linux distribution packages and HPC or datacenter node-monitoring stacks. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Upgrade FreeIPMI to 1.6.19 or later, or install vendor/distro security backports as they become available, prioritizing management and monitoring hosts where FreeIPMI runs privileged. Inventory which systems have FreeIPMI installed and check the reported version before and after patching. Because the bug is triggered by BMC responses, keeping BMC firmware current and restricting IPMI (especially remote LAN) access to trusted parties reduces the likelihood that an oversized FRU response can be delivered.
Affected
| GNU FreeIPMI project FreeIPMI | all versions before 1.6.19 |
Estimated exposure
large≈100,000+ server/cluster installations (rough order-of-magnitude estimate) — FreeIPMI ships in the package repositories of all major Linux distributions and is a standard node-health/BMC monitoring tool in HPC and enterprise data centers, but it is not typically internet-exposed and no public install counts exist,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.