CVE-2026-85507: Buffer Overflow
Published Sep 4, 2026
·Updated
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in outputdellsysteminfocmcinfo in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
Affected Software
1 affected component
ipmi-oem/ipmi-oem-dell.c<1.6.19
Event History
Sep 4, 2026
CVE Published
via MITRE·04:18 AM
Data Sourced
via MITRE·04:18 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which FreeIPMI versions are affected?
FreeIPMI releases before 1.6.19 are affected. The issue is in the ipmi-oem utility's Dell-specific implementation.
2
What conditions are required to exploit this issue?
The provided vector indicates network-based exploitation with low attack complexity, no privileges, and no user interaction. The vulnerable code path is associated with the cmc-info subcommand used by dell get-system-info.
3
What is the impact of successful exploitation?
Successful exploitation can result in high impact to confidentiality, integrity, and availability. The flaw is a stack-based buffer overflow.