CVE-2026-85505: High severity ipmi-oem/ipmi-oem-fujitsu.c vulnerability
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmioemfujitsugetselentrylongtext in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeIPMI ipmi-oemto a version that resolves this vulnerability.Fixed in 1.6.19
Event History
Frequently Asked Questions
What must an attacker be able to do to trigger the issue?
An attacker needs to cause a BMC to provide a short response to ipmi_oem_fujitsu_get_sel_entry_long_text. The reported vector is network-accessible and requires neither privileges nor user interaction.
What impact is reported from successful exploitation?
The vulnerability is reported as a stack-based buffer over-read that can cause a denial of service. The supplied severity vector indicates no reported confidentiality or integrity impact.
Which FreeIPMI versions need remediation?
FreeIPMI versions before 1.6.19 are affected. Update to 1.6.19 or later.
Is this the same issue as CVE-2026-50031?
No. It is explicitly identified as a different vulnerability from CVE-2026-50031, and the two issues have different affected-version ranges.