Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85507

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

A flaw was found in FreeIPMI. A local attacker can exploit a stack-based buffer overflow vulnerability in the ipmi-oem utility when processing the dell get-system-info cmc-info subcommand. This can lead to arbitrary code execution, allowing the attacker to run malicious code on the affected system.

Отчет

A stack-based buffer overflow in the FreeIPMI ipmi-oem utility can lead to arbitrary code execution when processing the dell get-system-info cmc-info subcommand. This vulnerability is classified as Moderate because the high potential impact (arbitrary code execution) is offset by limited exploitability: an attacker must already possess local access to the system and intentionally execute this specific subcommand to trigger the flaw.

Меры по смягчению последствий

Restrict IPMI and BMC access to a dedicated, trusted management network so ipmi-oem cannot reach untrusted or compromised controllers. Please do not run ipmi-oem dell get-system-info cmc-info against untrusted BMCs. If that Dell CMC query is not required, do not use ipmi-oem against remote management controllers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freeipmiAffected
Red Hat Enterprise Linux 6freeipmiNot affected
Red Hat Enterprise Linux 7freeipmiAffected
Red Hat Enterprise Linux 8freeipmiAffected
Red Hat Enterprise Linux 9freeipmiAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2528396FreeIPMI: FreeIPMI: Arbitrary code execution via stack-based buffer overflow

EPSS

Процентиль: 32%
0.00388
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

CVSS3: 9.8
nvd
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

msrc
8 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

CVSS3: 9.8
debian
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow i ...

CVSS3: 9.8
github
12 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

EPSS

Процентиль: 32%
0.00388
Низкий

7.5 High

CVSS3