UbuntuUpdates.org

Package "freeipmi"

Name: freeipmi

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GNU implementation of the IPMI protocol - common files
  • GNU implementation of the IPMI protocol - tools
  • GNU IPMI - development package
  • GNU IPMI - libraries

Latest version: 1.6.16-1ubuntu0.2
Release: resolute (26.04)
Level: updates
Repository: main

Links



Other versions of "freeipmi" in Resolute

Repository Area Version
base main 1.6.16-1
base universe 1.6.16-1
security universe 1.6.16-1ubuntu0.2
security main 1.6.16-1ubuntu0.2
updates universe 1.6.16-1ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.6.16-1ubuntu0.2 2026-09-29 17:07:21 UTC

freeipmi (1.6.16-1ubuntu0.2) resolute-security; urgency=medium

  * SECURITY UPDATE: stack overflow in libfreeipmi Fujitsu SEL parsing
    - debian/patches/CVE-2026-85504.patch: reject short and oversized
      responses and bound each text chunk in
      libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c.
    - CVE-2026-85504
  * SECURITY UPDATE: stack over-read in ipmi-oem Fujitsu SEL long-text
    - debian/patches/CVE-2026-85505.patch: copy only the remaining
      data_length bytes in ipmi-oem/ipmi-oem-fujitsu.c.
    - CVE-2026-85505
  * SECURITY UPDATE: stack overflow in ipmi-oem Dell idrac-info
    - debian/patches/CVE-2026-85506.patch: check idrac_info buffer size
      before copying in ipmi-oem/ipmi-oem-dell.c.
    - CVE-2026-85506
  * SECURITY UPDATE: stack overflow in ipmi-oem Dell cmc-info
    - debian/patches/CVE-2026-85507.patch: check cmc_info buffer size
      before copying in ipmi-oem/ipmi-oem-dell.c.
    - CVE-2026-85507
  * SECURITY UPDATE: stack overflow in ipmi-oem Dell cmc-ipv6-info
    - debian/patches/CVE-2026-85508.patch: check cmc_ipv6_info buffer size
      before copying in ipmi-oem/ipmi-oem-dell.c.
    - CVE-2026-85508
  * SECURITY UPDATE: stack overflow in libfreeipmi FRU reading
    - debian/patches/CVE-2026-85509.patch: reject a count_returned larger
      than requested in libfreeipmi/fru/ipmi-fru.c.
    - CVE-2026-85509

 -- Charles Cochran Fri, 25 Sep 2026 15:46:47 -0400

Source diff to previous version
CVE-2026-85504 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-
CVE-2026-85505 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when
CVE-2026-85506 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subc
CVE-2026-85507 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subco
CVE-2026-85508 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-
CVE-2026-85509 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested

Version: 1.6.16-1ubuntu0.1 2026-07-27 17:08:09 UTC
No changelog available yet.



About   -   Send Feedback to @ubuntu_updates