Home / Alt manpages / dmidecode(8)

  • dmidecode(8)
  • Admin command
  • linux

Read BIOS and Hardware Inventory Safely with dmidecode

You will use dmidecode to inspect the SMBIOS data your firmware exposes, extract one field for a script, and save a binary dump for later analysis. Allow about ten minutes. You need the dmidecode package and, for live table reads on most Linux systems, elevated privileges. The examples here use dmidecode 3.5 from Ubuntu package version 3.5-3ubuntu0.1.

1. Check the installed command

Start with read-only checks. They do not need sudo:

$ command -v dmidecode
/usr/sbin/dmidecode
$ dmidecode --version
3.5
$ dpkg-query -W -f='${Package} ${Version}\n' dmidecode
dmidecode 3.5-3ubuntu0.1

Your path and package revision can differ. Keep the version with any inventory report because supported SMBIOS fields and output details can change between releases.

Checkpoint

If command -v finds nothing, install the package through your normal distribution process. Do not copy a random binary into /usr/sbin.

2. Read a focused system record

A full dump is useful when investigating a machine, but it can contain serial numbers, UUIDs and asset tags. Begin with the system records and review the output before sharing it:

$ sudo dmidecode --type system
# dmidecode 3.5
Getting SMBIOS data from sysfs.
SMBIOS 3.0.0 present.

Handle 0x0001, DMI type 1, 27 bytes
System Information
        Manufacturer: FUJITSU
        Product Name: [machine-specific]
        Serial Number: [machine-specific]
        UUID: [machine-specific]

The exact records and values belong to your firmware. A type keyword selects a group: bios, system, baseboard, chassis, processor, memory, cache, connector or slot. A keyword is not a hardware probe. It reports what the BIOS or other firmware placed in the DMI table.

Use --quiet when you want less metadata and fewer unknown or OEM-specific entries:

$ sudo dmidecode --quiet --type system

Do not treat a successful exit status as proof that every value is correct. The installed manual explicitly warns that DMI data may be inaccurate, incomplete or wrong.

3. Extract one value

For a report or a shell check, --string returns one named DMI string rather than a record listing:

$ sudo dmidecode --string system-manufacturer
FUJITSU
$ sudo dmidecode --string bios-version
[firmware-specific value]

Useful keywords include system-product-name, system-serial-number, system-uuid, baseboard-product-name, chassis-asset-tag, processor-version and processor-frequency. Some return more than one result on a multi-processor system, and some are empty or undefined on particular machines.

Do not put a secret-bearing result into a command log. Serial numbers, UUIDs and asset tags are identifiers, not harmless sample data. If you only need to test availability, inspect the exit status without printing the value:

$ if sudo dmidecode --string system-serial-number >/dev/null; then
>     echo 'system serial field read successfully'
> else
>     echo 'system serial field could not be read'
> fi
system serial field read successfully

4. Select records by type or handle

Use a numeric type when you need a precise SMBIOS record. Type 17 is a memory device, while type 4 is a processor:

$ sudo dmidecode --type 17
$ sudo dmidecode --type 4

Multiple --type options form a union. These commands are equivalent:

$ sudo dmidecode --type 0 --type 13
$ sudo dmidecode --type 0,13
$ sudo dmidecode --type bios

Every decoded record has a handle. Once a full or focused listing shows a handle such as 0x0001, ask for just that entry:

$ sudo dmidecode --handle 0x0001

Handles are 16-bit integers. They are useful for reducing noise, but they are not guaranteed to identify the same component across different machines or firmware revisions.

5. Save a dump without overwriting a file

--dump-bin writes the raw DMI data to a binary file that can later be read with --from-dump. The destination must not already exist, so choose a new path and check it first:

$ dump=/tmp/dmidecode-$(hostname)-$(date +%Y%m%d).bin
$ if test -e "$dump"; then
>     echo "Refusing to overwrite $dump" >&2
>     exit 1
> fi
$ sudo dmidecode --dump-bin "$dump"
$ test -s "$dump" && echo "wrote $dump"
wrote /tmp/[host]-[date].bin

The dump can contain the same identifying information as the live output. Treat it as sensitive and restrict access if you move it off the machine. To inspect it later, pass it to --from-dump; no live firmware read is needed:

$ sudo dmidecode --from-dump "$dump" --type system

The command reads the file and does not change it. Remove a temporary dump only after you have confirmed that no investigation needs it. That removal is irreversible:

$ rm -- "$dump"

6. Diagnose permissions and unreliable results

On Linux, dmidecode first tries the DMI tables exposed through sysfs and then may try /dev/mem. A regular user can therefore see a permission error even when the command is installed correctly:

$ dmidecode --type system
/sys/firmware/dmi/tables/smbios_entry_point: Permission denied
Can't read memory from /dev/mem

Retry with sudo if your policy permits it. Do not make /dev/mem broadly readable to avoid using elevated privileges. The Linux files /sys/firmware/dmi/tables/smbios_entry_point and /sys/firmware/dmi/tables/DMI are the documented table locations, but their permissions are controlled by the system.

If a keyword is misspelled, dmidecode prints the valid keyword list and exits with an error. If the firmware advertises an SMBIOS version newer than the installed tool supports, the command warns that the decoded data may not be reliable. Upgrade the package through your distribution rather than guessing at fields. Finally, compare suspicious values with the machine's firmware setup or vendor documentation. dmidecode decodes firmware claims; it does not independently discover the hardware.

Done means

  • You confirmed the installed dmidecode version and package revision.
  • You used sudo only for the table read, where required.
  • You selected a record or string instead of sharing an unnecessary full dump.
  • You treated serial numbers, UUIDs, asset tags and saved dumps as sensitive.
  • You checked suspicious or blank values against another authoritative source.