Buffer Overflow Vulnerability in FreeIPMI Affects GNU Project Products
CVE-2026-85504

9.8CRITICAL

Key Information:

Vendor

Freeipmi

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85504?

The FreeIPMI software, utilized within various GNU Project products, is vulnerable to a stack-based buffer overflow. This threat arises from the function _ipmi_sel_oem_fujitsu_get_sel_entry_long_text, specifically when processing malformed responses from Fujitsu System Event Log (SEL). Versions prior to 1.6.19 remain susceptible, potentially allowing an attacker to exploit this flaw, leading to unauthorized code execution or system compromise if the affected system interacts with such malformed SEL responses.

Affected Version(s)

FreeIPMI 0 < 1.6.19

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.