CVE-2026-85508: Buffer Overflow
Published Sep 4, 2026
·Updated
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in outputdellsysteminfocmcipv6info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
Affected Software
1 affected component
FreeIPMI ipmi-oem/ipmi-oem-dell<1.6.19
Event History
Sep 4, 2026
CVE Published
via MITRE·04:20 AM
Data Sourced
via MITRE·04:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which versions are affected?
FreeIPMI versions before 1.6.19 are affected in the ipmi-oem Dell implementation.
2
What component and operation trigger the overflow?
The stack-based buffer overflow is in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c. It is associated with the cmc-ipv6-info subcommand of dell get-system-info.
3
Is authentication or user interaction required according to the severity vector?
The supplied vector indicates network attackability with low complexity and no required privileges or user interaction. It also indicates high impact to confidentiality, integrity, and availability.