CVE-2026-85508

9.8

FreeIPMI · FreeIPMI

FreeIPMI is vulnerable to a stack-based buffer overflow in the ipmi-oem component via the cmc-ipv6-info subcommand, potentially allowing remote code execution.

Executive summary

A critical stack-based buffer overflow in FreeIPMI allows unauthenticated remote attackers to execute arbitrary code with the privileges of the application.

Vulnerability

The vulnerability is a stack-based buffer overflow (CWE-121) located in the _output_dell_system_info_cmc_ipv6_info function within the ipmi-oem-dell.c source file. An unauthenticated attacker can trigger this flaw by providing malicious input to the cmc-ipv6-info subcommand.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical risk to infrastructure integrity. Successful exploitation could lead to full system compromise, unauthorized data access, and persistent service disruption, presenting a severe threat to operational continuity and data confidentiality.

Remediation

Immediate Action: Update the FreeIPMI software to version 1.6.19 or later, which contains the necessary security fixes.

Proactive Monitoring: Monitor system logs for unusual crashes or malformed requests directed toward IPMI management services, as these may indicate exploitation attempts.

Compensating Controls: Restrict network access to IPMI interfaces to trusted management networks only, effectively isolating the vulnerable service from public-facing or untrusted segments.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the critical nature of this buffer overflow and the potential for remote code execution, organizations must prioritize the deployment of FreeIPMI version 1.6.19 immediately. Failure to patch this vulnerability leaves management interfaces exposed to potential takeover by unauthenticated actors, which could facilitate broader lateral movement within the data center.

More FreeIPMI CVEs

Sources