← Terug naar overzicht

A stack-based buffer overflow vulnerability has been identified in FreeIPMI versions prior to 1.6.19. The flaw exists in the _get_dell_system_info_idrac_info function within ipmi-oem/ipmi-oem-dell.c, triggered via the idrac-info subcommand of the dell get-system-info operation. An attacker exploiting this vulnerability could potentially execute arbitrary code or cause a denial of service condition. The vulnerability affects the ipmi-oem component specifically when interacting with Dell iDRAC systems. The fix is available in FreeIPMI version 1.6.19, released and available via the GNU FTP server. Users are advised to upgrade to version 1.6.19 or later to mitigate the risk. The vulnerability was disclosed on the oss-security mailing list in August 2026.

Affected products

  • Dell iDRAC
  • FreeIPMI before 1.6.19
  • ipmi-oem

Related CVE's

  • CVE-2026-85506

Categories

  • Critical Infrastructure
  • Network Infrastructure