Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85506

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

A flaw was found in FreeIPMI. A stack-based buffer overflow in the ipmi-oem utility can lead to arbitrary code execution. This vulnerability can be exploited by a local user who executes a specially crafted ipmi-oem command, potentially when processing untrusted data from a remote source.

Отчет

A stack-based buffer overflow vulnerability in the ipmi-oem utility of FreeIPMI could allow a local attacker to execute arbitrary code. To exploit this moderate-severity flaw, a local user must be tricked into running a specially crafted command that processes untrusted data. The requirement for local access and active user interaction significantly increases the overall complexity of the attack.

Меры по смягчению последствий

To mitigate this vulnerability, implement robust boundary checks before copying data to ensure the input size does not exceed the allocated stack buffer capacity. Developers should replace unsafe, unbounded memory functions (like strcpy or sprintf) with safe, length-restricted alternatives (such as strncpy or snprintf). Furthermore, deploying the application in environments that enforce compiler-based protections like stack canaries and Address Space Layout Randomization (ASLR) will prevent successful code execution

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freeipmiAffected
Red Hat Enterprise Linux 6freeipmiNot affected
Red Hat Enterprise Linux 7freeipmiNot affected
Red Hat Enterprise Linux 8freeipmiAffected
Red Hat Enterprise Linux 9freeipmiAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2528398FreeIPMI: FreeIPMI: Arbitrary code execution via stack-based buffer overflow in ipmi-oem

EPSS

Процентиль: 32%
0.00388
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

CVSS3: 9.8
nvd
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

msrc
8 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

CVSS3: 9.8
debian
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow i ...

CVSS3: 9.8
github
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

EPSS

Процентиль: 32%
0.00388
Низкий

7.5 High

CVSS3