← Terug naar overzicht

CVE-2026-85509 describes a stack-based buffer overflow vulnerability in FreeIPMI versions prior to 1.6.19. The flaw exists in the _read_fru_data function within libfreeipmi/fru/ipmi-fru.c. The vulnerability is triggered when a Baseboard Management Controller (BMC) returns more bytes than were originally requested during FRU data reads. This type of stack overflow can potentially allow attackers to execute arbitrary code or crash the affected system. The issue has been patched in FreeIPMI version 1.6.19. Users are advised to upgrade to the fixed version immediately. The vulnerability was disclosed via the oss-security mailing list. FreeIPMI is a GNU project providing IPMI management utilities widely used in server infrastructure environments.

Affected products

  • FreeIPMI before 1.6.19

Related CVE's

  • CVE-2026-85509

Categories

  • Critical Infrastructure
  • Network Infrastructure