Skip to content
Critical Buffer Overflow Vulnerabilities in FreeIPMI Affect Ubuntu Systems

Critical Buffer Overflow Vulnerabilities in FreeIPMI Affect Ubuntu Systems

First seen 27 Jul 2026, 19:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 28, 2026 at 15:18 UTC
  • FreeIPMI vulnerabilities could lead to denial of service if exploited.
  • Local attackers with malicious IPMI devices can trigger crashes in FreeIPMI.
  • Users should update to patched versions of freeipmi-tools across supported Ubuntu LTS releases.

Multiple buffer overflow vulnerabilities were discovered in FreeIPMI by Zhihan Zheng, affecting various Ubuntu versions. These vulnerabilities (CVE-2026-33554, CVE-2026-50031) allow local attackers controlling a malicious IPMI device to crash FreeIPMI, leading to denial of service. Affected versions include freeipmi-tools across Ubuntu LTS releases from 14.04 to 26.04. Users are advised to update their systems to mitigate these vulnerabilities. The vulnerabilities were published on March 24, 2026, and June 3, 2026, respectively. A standard system update is recommended to apply the necessary patches. Ubuntu Pro offers extended support for affected versions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 54d ago How this analysis works

Timeline

2026-03-24
CVE-2026-33554 published
Buffer overflow vulnerability in FreeIPMI discovered, allowing potential denial of service.
Linuxsecurity
2026-06-03
CVE-2026-50031 published
Another buffer overflow vulnerability in FreeIPMI identified, similar in impact to CVE-2026-33554.
Linuxsecurity
2026-07-27
Advisory USN-8613-1 released
Ubuntu released an advisory detailing the vulnerabilities and recommended updates for affected systems.
Ubuntu

More articles in this cluster (3)

Following this threat?

Track CVE-2026-33554 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed