← Back to overview

A stack-based buffer overflow vulnerability has been identified in FreeIPMI versions prior to 1.6.19. The flaw exists in the ipmi-oem component, specifically within the _output_dell_system_info_cmc_info function located in ipmi-oem/ipmi-oem-dell.c. The vulnerability is triggered via the cmc-info subcommand of the dell get-system-info operation. Stack-based buffer overflows can potentially allow attackers to execute arbitrary code or cause a denial of service. The vulnerability has been assigned CVE-2026-85507 and is tracked by NVD. A patched version, FreeIPMI 1.6.19, has been released and is available via the GNU FTP server. The issue was disclosed on the oss-security mailing list in August 2026. Users are advised to upgrade to FreeIPMI 1.6.19 or later to mitigate the risk.

Affected products

  • FreeIPMI before 1.6.19

Related CVE's

  • CVE-2026-85507

Categories

  • Critical Infrastructure
  • Network Infrastructure