[ubuntu/jammy-security] freeipmi 1.6.9-2ubuntu0.22.04.3 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Mon Jul 27 14:20:56 UTC 2026


freeipmi (1.6.9-2ubuntu0.22.04.3) jammy-security; urgency=medium

  * SECURITY UPDATE: memory out of bounds errors
    - debian/patches/CVE-2026-33554.patch: set bounds for memcpy operations in
      ipmi-oem/ipmi-oem-dell.c, ipmi-oem/ipmi-oem-supermicro.c,
      ipmi-oem/ipmi-oem-wistron.c.
    - CVE-2026-33554
  * SECURITY UPDATE: potential stack corruption & overflow
    - debian/patches/CVE-2026-50031-1.patch: correct length of token_data
      buffer from 256 to 65536 bytes in ipmi-oem/ipmi-oem-dell.c.
    - debian/patches/CVE-2026-50031-2.patch: set upper bound of data_length in
      ipmi-oem/ipmi-oem-fujitsu.c.
    - CVE-2026-50031

Date: 2026-07-23 20:47:27.712066+00:00
Changed-By: Charles Cochran <charles.cochran at canonical.com>
Signed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list