CVE-2026-50031 Details
Description
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages.
A buffer overflow vulnerability has been identified in FreeIPMI versions prior to 1.16.18, specifically within the ipmi-oem component. This vulnerability arises from improper handling of response messages in certain subcommands, leading to exploitable buffer overflows. The affected subcommands are 'ipmi-oem dell get-active-directory-config' and 'ipmi-oem fujitsu get-sel-entry-long-text'. When these commands are executed, a malicious or compromised BMC (Baseboard Management Controller) can send responses that exceed the allocated buffer size, potentially corrupting stack memory and causing the ipmi-oem process to crash. Depending on the system's compiler options and runtime mitigations, this stack corruption could be exploited to hijack control flow and execute arbitrary code.
Users can upgrade to FreeIPMI version 1.16.18 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | New CVE Received | [email protected] |