[ubuntu/noble-security] freeipmi 1.6.13-3ubuntu0.1 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Mon Jul 27 14:20:54 UTC 2026
freeipmi (1.6.13-3ubuntu0.1) noble-security; urgency=medium
* SECURITY UPDATE: memory out of bounds errors
- debian/patches/CVE-2026-33554.patch: set bounds for memcpy operations in
ipmi-oem/ipmi-oem-dell.c, ipmi-oem/ipmi-oem-supermicro.c,
ipmi-oem/ipmi-oem-wistron.c.
- CVE-2026-33554
* SECURITY UPDATE: potential stack corruption & overflow
- debian/patches/CVE-2026-50031-1.patch: correct length of token_data
buffer from 256 to 65536 bytes in ipmi-oem/ipmi-oem-dell.c.
- debian/patches/CVE-2026-50031-2.patch: set upper bound of data_length in
ipmi-oem/ipmi-oem-fujitsu.c.
- CVE-2026-50031
Date: 2026-07-23 20:46:00.499163+00:00
Changed-By: Charles Cochran <charles.cochran at canonical.com>
Signed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list