CVE-2026-85509: Buffer Overflow
Published Sep 4, 2026
·Updated
FreeIPMI before 1.6.19 has a stack-based buffer overflow in readfrudata in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
Affected Software
1 affected component
FreeIPMI<1.6.19
Event History
Sep 4, 2026
CVE Published
via MITRE·04:21 AM
Data Sourced
via MITRE·04:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access is required to exploit this issue?
The vulnerability is network-reachable and requires neither privileges nor user interaction. Exploitation depends on a BMC returning more FRU data bytes than requested.
2
Which FreeIPMI versions are affected?
FreeIPMI versions before 1.6.19 are affected. Updating to version 1.6.19 or later removes systems from the stated affected version range.
3
How severe could successful exploitation be?
The reported CVSS vector rates it critical at 9.8 and indicates potential high impact to confidentiality, integrity, and availability.