CVE-2026-85505
Received Received - Intake

ipmi-oem Stack-Based Buffer Over-Read in FreeIPMI

Vulnerability report for CVE-2026-85505, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freeipmi ipmi-oem to 1.6.19 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer over-read vulnerability in the ipmi-oem component of FreeIPMI before version 1.6.19. It occurs specifically in the function ipmi_oem_fujitsu_get_sel_entry_long_text when a Baseboard Management Controller (BMC) provides a short response. This issue differs from CVE-2026-50031, which has different affected versions.

Detection Guidance

This vulnerability is specific to FreeIPMI versions before 1.6.19 and involves a stack-based buffer over-read in the ipmi_oem_fujitsu_get_sel_entry_long_text function. Detection requires checking the installed version of FreeIPMI on your system. Use the command 'ipmi-oem --version' to verify the version. If the version is below 1.6.19, the system is vulnerable.

Impact Analysis

This vulnerability could allow an attacker to read sensitive memory contents from the affected system. Since it is a stack-based buffer over-read, it may lead to information disclosure. The impact is rated high for availability (A:H) in the CVSS score, indicating potential system instability or crashes.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with standards like GDPR or HIPAA. The vulnerability involves a stack-based buffer over-read in FreeIPMI, which could potentially lead to information disclosure or system instability. However, without explicit details on data exposure or regulatory implications, its direct effect on compliance cannot be determined from the given context.

Mitigation Strategies

Update FreeIPMI to version 1.6.19 or later to address the stack-based buffer over-read in ipmi-oem.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85505. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart