Stack-Based Buffer Overflow Vulnerability in FreeIPMI by GNU
CVE-2026-85507
9.8CRITICAL
What is CVE-2026-85507?
A vulnerability exists in the ipmi-oem component of FreeIPMI, specifically affecting versions prior to 1.6.19. This issue is due to a stack-based buffer overflow in the function _output_dell_system_info_cmc_info found in ipmi-oem/ipmi-oem-dell.c. The vulnerability arises when processing the cmc-info subcommand used to retrieve system information, potentially allowing attackers to exploit this overflow to execute arbitrary code. It is essential for users of FreeIPMI to update to version 1.6.19 or later to mitigate any risks associated with this vulnerability.
Affected Version(s)
FreeIPMI 0 < 1.6.19
