CVE-2026-85506
9.8FreeIPMI · FreeIPMI
A stack-based buffer overflow in the ipmi-oem utility of FreeIPMI allows for potential remote code execution via the idrac-info subcommand.
Executive summary
A critical stack-based buffer overflow vulnerability in FreeIPMI versions prior to 1.6.19 could allow an unauthenticated remote attacker to execute arbitrary code with elevated privileges.
Vulnerability
This vulnerability is a stack-based buffer overflow located in the _get_dell_system_info_idrac_info function within the ipmi-oem component. The flaw is reachable by an unauthenticated attacker via the idrac-info subcommand.
Business impact
The vulnerability carries a CVSS score of 9.8, reflecting its critical nature and the potential for full system compromise. Successful exploitation could lead to unauthorized remote code execution, resulting in total loss of confidentiality, integrity, and availability for the affected host, which may cause significant operational downtime and data exposure.
Remediation
Immediate Action: Update FreeIPMI to version 1.6.19 or later as provided by the vendor.
Proactive Monitoring: Review system and application logs for unusual crashes or unexpected execution patterns involving the ipmi-oem utility.
Compensating Controls: Implement network access controls to restrict access to IPMI interfaces to trusted management networks only, thereby reducing the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity and the potential for unauthenticated remote code execution, organizations should prioritize patching FreeIPMI immediately. System administrators must ensure that all instances of FreeIPMI are updated to version 1.6.19 or higher to eliminate this high-risk vulnerability.