SB20260529114 - Excessive Iteration in Linux kernel char ipmi driver
Published: May 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Excessive Iteration (CVE-ID: CVE-2026-46177)
CWE-ID: CWE-834 - Excessive Iteration
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper restriction of excessive iteration in the ipmi driver when processing event and receive message fetches from a BMC that continues reporting available data. A local user can trigger interaction with a malfunctioning or malicious BMC to cause a denial of service.
The issue can also be triggered when the si interface attention state remains stuck and repeatedly causes flag fetch handling.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3d37d2165df9504ea99d9e6181552dc4d2d1ab37
- https://git.kernel.org/stable/c/67c44e0deba936d5edaebea356b4589eb43acb5c
- https://git.kernel.org/stable/c/c024167fb00489baee08c72182ca2e7dc5fb9f20
- https://git.kernel.org/stable/c/c4cca236968683eb0d59abfb12d5c7e4d8514227
- https://git.kernel.org/stable/c/e20212b431bef217d3886b86bbc90cc3ed00de68