Description
In the Linux kernel, the following vulnerability has been resolved:

ipmi: ipmb: validate write message length

ipmb_write() read message fields before validating the length byte.

A zero or short write can read uninitialized stack bytes.

A length smaller than the SMBus header underflows the block write length.

Require a non-empty buffer and the minimum IPMB request length.

Also require the length byte plus payload before parsing the message.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel IPMI IPMB stack, the write handler parses IPMI messages before validating write causes the routine to read uninitialized stack bytes, and a length smaller than the SMBus header underflows the block write length. Because the buffer and length are not checked up front, an attacker can supply crafted IPMI write commands that allow reading kernel memory contents. This improper input validation and use of uninitialized memory can lead to the disclosure of privileged data, impacting confidentiality but not integrity or availability.

Affected Systems

All Linux kernel releases that contain the IPMI IPMB stack could be affected, as the commit series referenced in the advisory introduces supplied in the advisory; therefore, any kernel prior to the inclusion of these commits remains vulnerable. Users should upgrade to a kernel that incorporates the patch commits 53637506884dbd5c91a89b1a3547d99d80f8ed2c, 5719431ca2b5fa26560bb38f6202f8b97fa3bbb0, 60939bcda6f3f104ef456fdbf3cc5733c0720fb1, or a84c6e3d188f2c6e674910929eb790634299d6d5.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity, and the EPSS score of less than 1% and absence from the CISA KEV catalog imply a low probability of public exploitation. Exploitation requires the ability to send custom IPMI write commands, which is typically restricted to privileged users or can be performed remotely through an external BMC if exposed. The likely attack vector is local or remote IPMI write operations that supply a message with an invalid length IPMI messaging can read kernel memory and potentially leak confidential data.

Generated by OpenCVE AI on September 21, 2026 at 03:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit series fixing the write length validation, such as the latest stable release or a backported patch.
  • If an upgrade is not immediately possible, disable the vulnerable IPMI IPMB module (e.g., add a blacklist entry for "ipmi_ipmb" in /etc/modprobe.d/blacklist.conf or run "modprobe -r ipmi_ipmb").
  • Restrict access to the IPMI interface by firewalling or network segmentation and ensure only trusted management hosts can issue write commands.
  • Consider disabling the IPMI subsystem entirely on systems that do not rely on remote management, or configure the BMC to reject or limit write operations with missing or malformed length bytes.

Generated by OpenCVE AI on September 21, 2026 at 03:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-788

Mon, 21 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-788

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-788

Sun, 13 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-126
CWE-20
CWE-665

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-126
CWE-20
CWE-665

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header underflows the block write length. Require a non-empty buffer and the minimum IPMB request length. Also require the length byte plus payload before parsing the message.
Title ipmi: ipmb: validate write message length
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:40.685Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-81007

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:09.443

Modified: 2026-09-14T13:18:55.033

Link: CVE-2026-81007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:45:08Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-788

    Access of Memory Location After End of Buffer