Series guide
3 posts Updated May 15, 2026
OpenBMC Security
Start with the OpenBMC architecture and lab setup, then follow the management-plane attack surface into two parser case studies. Each part connects the component model to a concrete vulnerability class and its defensive lessons.
Reading path
All posts
-
OpenBMC Security Part 1: Architecture, Attack Surface, and Lab Setup A practical and slide-backed walkthrough of OpenBMC architecture, attack surface, D-Bus, and a QEMU lab setup. 10 min read #OpenBMC#BMC#Security -
OpenBMC Security Part 2: bmcweb Multipart Parser CVEs A practical, slide-backed analysis of CVE-2022-2809 and CVE-2022-3409 in the bmcweb multipart parser. 7 min read #OpenBMC#bmcweb#CVE -
OpenBMC Security Part 3: slpd-lite and CVE-2024-41660 A practical, slide-backed analysis of CVE-2024-41660 in OpenBMC slpd-lite, focusing on SLP length fields and memory corruption. 7 min read #OpenBMC#slpd-lite#CVE