Junglewise Threat Intelligence

CVE-2026-85505: FreeIPMI ipmi-oem stack-based buffer over-read in Fujitsu SEL parsing

CVE-2026-85505 · Severity: high · CVSS 7.5 · Published 2026-09-04

Vendors: Gnu.

Executive brief

FreeIPMI is a suite of tools for IPMI-based system management, commonly used to monitor and control servers remotely. A vulnerability in the ipmi-oem tool allows a malicious or compromised BMC (baseboard management controller) to trigger a stack-based buffer over-read when processing certain system event log entries, potentially exposing sensitive information or causing a denial of service.

Technical details

The vulnerability is a stack-based buffer over-read in the ipmi_oem_fujitsu_get_sel_entry_long_text function within ipmi-oem/ipmi-oem-fujitsu.c. It occurs when a BMC provides a response shorter than expected while parsing Fujitsu-specific SEL (System Event Log) entries. The vulnerable code does not properly validate response length before dereferencing memory on the stack. An attacker with access to a BMC or the ability to intercept IPMI communication can trigger this condition. The impact includes information disclosure or denial of service. FreeIPMI version 1.6.19 and later contain a fix.

Affected products

  • GNU FreeIPMI before 1.6.19

Timeline

  • 2026-09-04: disclosed
  • 2026-08-27: patched: FreeIPMI 1.6.19 released

References