CVE-2026-85504: Buffer Overflow
Published Sep 4, 2026
·Updated
FreeIPMI before 1.6.19 has a stack-based buffer overflow in ipmiseloemfujitsugetselentrylongtext in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
Affected Software
1 affected component
libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c<1.6.19
Event History
Sep 4, 2026
CVE Published
via MITRE·04:14 AM
Data Sourced
via MITRE·04:14 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using FreeIPMI versions before 1.6.19 are affected when they process Fujitsu SEL long-text responses through the vulnerable SEL parsing code.
2
What must an attacker provide to trigger the overflow?
An attacker needs to cause malformed Fujitsu SEL long-text responses to be processed. The supplied severity vector indicates network reachability, low attack complexity, and no required privileges or user interaction.
3
What is the remediation?
Upgrade FreeIPMI to version 1.6.19 or later. The affected versions are those before 1.6.19.