freeipmi: FreeIPMI: stack-based buffer overflow in ipmi-oem Dell system info handler
Published Sep 4, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.40%
Description
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
Affected products
-
- Version 0StatusaffectedConstraints<1.6.19
- Version
No data.
No data.
Red Hat Enterprise Linux 10
freeipmi
Affected
Red Hat Enterprise Linux 6
freeipmi
Out of support scope
Red Hat Enterprise Linux 7
freeipmi
Affected
Red Hat Enterprise Linux 8
freeipmi
Affected
Red Hat Enterprise Linux 9
freeipmi
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | freeipmi | Affected | n/a |
| Red Hat Enterprise Linux 6 | freeipmi | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | freeipmi | Affected | n/a |
| Red Hat Enterprise Linux 8 | freeipmi | Affected | n/a |
| Red Hat Enterprise Linux 9 | freeipmi | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw has limited practical impact for several reasons: (1) ipmi-oem is a client-side command-line tool run manually by administrators, not a listening service or daemon — exploitation requires a user to actively run the specific Dell OEM subcommand against a compromised or malicious BMC; (2) IPMI communication typically occurs over a dedicated out-of-band management network, not the general Internet; (3) Red Hat Enterprise Linux builds FreeIPMI with full hardening enabled (_hardened_build 1), including stack protector (-fstack-protector-strong), which detects stack buffer corruption and terminates the process before the return address can be hijacked — effectively limiting the impact to a client-side crash rather than code execution; (4) additional mitigations including PIE, full RELRO, and NX further hinder exploitation even if the stack canary were bypassed. Fix is available in FreeIPMI version 1.6.19.
Red Hat mitigation
Do not run ipmi-oem dell get-system-info subcommands (specifically idrac-info, cmc-info, and cmc-ipv6-info) against untrusted or unverified BMC endpoints. Restrict IPMI management network access to trusted administrators and trusted BMC controllers only. If the ipmi-oem Dell OEM subcommands are not needed, avoid using them entirely.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Sep 4, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.40% (0.00405) | 32.41th | v5 (v2026.06.15) |
| Sep 4, 2026 | 0.39% (0.00388) | 32.00th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-85508 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2528401 Issue Tracking
- https://ftp.gnu.org/gnu/freeipmi/freeipmi-1.6.19.tar.gz
- https://nvd.nist.gov/vuln/detail/CVE-2026-85508
- https://www.cve.org/CVERecord?id=CVE-2026-85508
- https://www.gnu.org/software/freeipmi/
- https://www.openwall.com/lists/oss-security/2026/08/28/5
Change history (0)
No recorded changes yet.