[USN-8613-1] FreeIPMI vulnerabilities
noreply+usn-bot at canonical.com
noreply+usn-bot at canonical.com
Mon Jul 27 16:55:39 UTC 2026
==========================================================================
Ubuntu Security Notice USN-8613-1
July 27, 2026
FreeIPMI vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in FreeIPMI.
Software Description:
- freeipmi: in-band and out-of-band Intelligent Platform Management Interface
Details:
Zhihan Zheng discovered that FreeIPMI had several buffer overflow
vulnerabilities in ipmi-oem response message handling. A local attacker
with control a malicious IPMI device or simulator could possibly cause
FreeIPMI to crash, resulting in a denial of service. (CVE-2026-33554,
CVE-2026-50031)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
freeipmi-tools 1.6.16-1ubuntu0.1
Ubuntu 24.04 LTS
freeipmi-tools 1.6.13-3ubuntu0.1
Ubuntu 22.04 LTS
freeipmi-tools 1.6.9-2ubuntu0.22.04.3
Ubuntu 20.04 LTS
freeipmi-tools 1.6.4-3ubuntu1.1+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
freeipmi-tools 1.4.11-1.1ubuntu4.1+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
freeipmi-tools 1.4.11-1.1ubuntu4.1~0.16.04.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04 LTS
freeipmi-tools 1.1.5-3ubuntu3.3+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8613-1
CVE-2026-33554, CVE-2026-50031
Package Information:
https://launchpad.net/ubuntu/+source/freeipmi/1.6.16-1ubuntu0.1
https://launchpad.net/ubuntu/+source/freeipmi/1.6.13-3ubuntu0.1
https://launchpad.net/ubuntu/+source/freeipmi/1.6.9-2ubuntu0.22.04.3
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20260727/f12e294f/attachment.sig>
More information about the ubuntu-security-announce
mailing list