Stack-Based Buffer Overflow Vulnerability in FreeIPMI by GNU
CVE-2026-85507

9.8CRITICAL

Key Information:

Vendor

Freeipmi

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85507?

A vulnerability exists in the ipmi-oem component of FreeIPMI, specifically affecting versions prior to 1.6.19. This issue is due to a stack-based buffer overflow in the function _output_dell_system_info_cmc_info found in ipmi-oem/ipmi-oem-dell.c. The vulnerability arises when processing the cmc-info subcommand used to retrieve system information, potentially allowing attackers to exploit this overflow to execute arbitrary code. It is essential for users of FreeIPMI to update to version 1.6.19 or later to mitigate any risks associated with this vulnerability.

Affected Version(s)

FreeIPMI 0 < 1.6.19

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.