Amazon Linux 2027 Preview Security Advisory: ALAS2027-2026-104
Advisory Release Date: 2026-09-28 09:00 Pacific
Advisory Updated Date: 2026-09-28 09:00 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages. (CVE-2026-50031)
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. (CVE-2026-85504)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions). (CVE-2026-85505)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). (CVE-2026-85506)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). (CVE-2026-85507)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). (CVE-2026-85508)
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. (CVE-2026-85509)
Affected Packages:
freeipmi
Issue Correction:
Run yum update freeipmi to update your system.
aarch64:
freeipmi-ipmiseld-debuginfo-1.6.19-1.amzn2027.aarch64
freeipmi-ipmidetectd-debuginfo-1.6.19-1.amzn2027.aarch64
freeipmi-bmc-watchdog-debuginfo-1.6.19-1.amzn2027.aarch64
freeipmi-1.6.19-1.amzn2027.aarch64
freeipmi-ipmiseld-1.6.19-1.amzn2027.aarch64
freeipmi-bmc-watchdog-1.6.19-1.amzn2027.aarch64
freeipmi-ipmidetectd-1.6.19-1.amzn2027.aarch64
freeipmi-debuginfo-1.6.19-1.amzn2027.aarch64
freeipmi-devel-1.6.19-1.amzn2027.aarch64
freeipmi-debugsource-1.6.19-1.amzn2027.aarch64
src:
freeipmi-1.6.19-1.amzn2027.src
x86_64:
freeipmi-ipmiseld-debuginfo-1.6.19-1.amzn2027.x86_64
freeipmi-ipmidetectd-debuginfo-1.6.19-1.amzn2027.x86_64
freeipmi-bmc-watchdog-1.6.19-1.amzn2027.x86_64
freeipmi-bmc-watchdog-debuginfo-1.6.19-1.amzn2027.x86_64
freeipmi-debugsource-1.6.19-1.amzn2027.x86_64
freeipmi-1.6.19-1.amzn2027.x86_64
freeipmi-debuginfo-1.6.19-1.amzn2027.x86_64
freeipmi-ipmiseld-1.6.19-1.amzn2027.x86_64
freeipmi-devel-1.6.19-1.amzn2027.x86_64
freeipmi-ipmidetectd-1.6.19-1.amzn2027.x86_64