CVE-2026-85504
Received Received - Intake

Stack-Based Buffer Overflow in FreeIPMI Fujitsu SEL Handling

Vulnerability report for CVE-2026-85504, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freeipmi freeipmi to 1.6.19 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-85504 is a stack-based buffer overflow vulnerability in FreeIPMI versions before 1.6.19. It occurs in the function _ipmi_sel_oem_fujitsu_get_sel_entry_long_text within the libfreeipmi library. The flaw is triggered by malformed Fujitsu SEL long-text responses, which can lead to memory corruption.

Detection Guidance

To detect this vulnerability, check the FreeIPMI version installed on your system using 'ipmi-sel --version' or 'bmc-info --version'. If the version is below 1.6.19, the system is vulnerable. Monitor system logs for unusual SEL entries or crashes in FreeIPMI tools.

Impact Analysis

This vulnerability can allow attackers to execute arbitrary code, escalate privileges, or cause denial of service on affected systems. Since FreeIPMI is used for hardware management in HPC and cluster environments, successful exploitation could disrupt critical system operations or grant unauthorized access to sensitive hardware controls.

Compliance Impact

The vulnerability is a stack-based buffer overflow in FreeIPMI's Fujitsu SEL long-text handling, allowing arbitrary code execution or denial of service. This could lead to unauthorized access to sensitive system data, potentially violating GDPR's data protection requirements or HIPAA's security rules for protected health information if exploited on systems handling such data.

Mitigation Strategies

Immediately update FreeIPMI to version 1.6.19 or later by downloading the latest release from the official GNU FTP server. After updating, restart any FreeIPMI services and verify the new version is running. Isolate affected systems if possible until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85504. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart