Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85505

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

A stack-based out-of-bounds read vulnerability was found in the FreeIPMI ipmi-oem utility. When processing an abnormally short response from a Baseboard Management Controller (BMC), the application over-reads the buffer. A malicious BMC could exploit this to crash the client application (Denial of Service) or potentially leak stack memory. Red Hat compiler safeguards further restrict the impact primarily to a process crash.

Отчет

A flaw in the ipmi_oem_fujitsu_get_sel_entry_long_text function of FreeIPMI allows an out-of-bounds read. If a BMC returns an unexpectedly truncated System Event Log (SEL) response, the client fails to validate the data length before reading. This causes the application to read past the allocated stack buffer boundaries, leading to a crash or potential memory disclosure.

Меры по смягчению последствий

Restrict IPMI and BMC access to a dedicated, trusted management network so ipmi-oem cannot reach untrusted or compromised Fujitsu controllers. Until a fixed freeipmi package is installed, do not run ipmi-oem fujitsu get-sel-entry-long-text against untrusted BMCs. If that OEM SEL long-text query is not required, do not use ipmi-oem against remote management controllers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freeipmiAffected
Red Hat Enterprise Linux 6freeipmiOut of support scope
Red Hat Enterprise Linux 7freeipmiAffected
Red Hat Enterprise Linux 8freeipmiAffected
Red Hat Enterprise Linux 9freeipmiAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2528400FreeIPMI: FreeIPMI: Denial of Service via stack-based buffer over-read in ipmi-oem

EPSS

Процентиль: 27%
0.00339
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

CVSS3: 7.5
nvd
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

msrc
11 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

CVSS3: 7.5
debian
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read ...

CVSS3: 7.5
github
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

EPSS

Процентиль: 27%
0.00339
Низкий

6.5 Medium

CVSS3