Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85504

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

A flaw was found in FreeIPMI. This vulnerability, a stack-based buffer overflow, occurs when the software processes malformed Fujitsu System Event Log (SEL) responses. An attacker could exploit this by providing specially crafted SEL data, potentially requiring user interaction, to achieve arbitrary code execution.

Отчет

A stack-based buffer overflow in FreeIPMI allows for arbitrary code execution when processing malformed Fujitsu System Event Log (SEL) responses. This vulnerability is restricted to a Moderate severity rating due to its elevated attack complexity: successful exploitation requires an attacker to successfully inject specially crafted SEL data and relies on active user interaction to trigger the vulnerable code path, significantly lowering the likelihood of an automated or widespread attack.

Меры по смягчению последствий

Restrict IPMI and BMC access to a dedicated, trusted management network so FreeIPMI SEL tools cannot reach untrusted or compromised Fujitsu controllers. Please do not run ipmi-sel with OEM interpretation (--interpret-oem-data) against untrusted BMCs, and do not enable interpret-oem-data in ipmiseld for those hosts. If Fujitsu OEM long-text SEL decoding is not required, leave that option off.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freeipmiAffected
Red Hat Enterprise Linux 6freeipmiOut of support scope
Red Hat Enterprise Linux 7freeipmiAffected
Red Hat Enterprise Linux 8freeipmiAffected
Red Hat Enterprise Linux 9freeipmiAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2528390FreeIPMI: FreeIPMI: Arbitrary code execution via malformed Fujitsu System Event Log responses

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

CVSS3: 9.8
nvd
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

msrc
11 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

CVSS3: 9.8
debian
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_ ...

CVSS3: 9.8
github
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

7.5 High

CVSS3