CVE-2026-85504

9.8

FreeIPMI · FreeIPMI

FreeIPMI is vulnerable to a stack-based buffer overflow in the Fujitsu SEL long-text response handling, potentially allowing unauthenticated remote code execution.

Executive summary

A critical stack-based buffer overflow in FreeIPMI versions prior to 1.6.19 exposes systems to potential remote code execution by unauthenticated attackers.

Vulnerability

The vulnerability is a stack-based buffer overflow (CWE-121) located in the _ipmi_sel_oem_fujitsu_get_sel_entry_long_text function within libfreeipmi. An unauthenticated remote attacker can trigger this flaw by providing a malformed Fujitsu SEL long-text response.

Business impact

The CVSS score of 9.8 reflects the high potential for full system compromise. Successful exploitation allows an attacker to gain arbitrary code execution, which may lead to complete loss of confidentiality, integrity, and availability of the affected host. This presents a severe risk to infrastructure management environments where FreeIPMI is deployed.

Remediation

Immediate Action: Update the FreeIPMI software to version 1.6.19 or later immediately.

Proactive Monitoring: Monitor system logs for unusual crashes or service restarts related to the IPMI management process, which may indicate exploitation attempts.

Compensating Controls: Restrict network access to IPMI management interfaces to trusted management subnets only, effectively isolating the service from untrusted networks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the unauthenticated nature of the attack vector, this vulnerability poses a significant risk to affected systems. Administrators should prioritize upgrading to version 1.6.19 as soon as possible to eliminate the buffer overflow condition. If immediate patching is not feasible, ensure that IPMI interfaces are strictly firewalled to prevent unauthorized network interaction.

More FreeIPMI CVEs

Sources