Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85509

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

A flaw was found in FreeIPMI. This vulnerability involves a stack-based buffer overflow that occurs when a Baseboard Management Controller (BMC) sends an oversized response during data reading. An attacker could exploit this by tricking an administrator into running FreeIPMI commands against a malicious BMC. Successful exploitation could lead to arbitrary code execution, allowing the attacker to run their own code on the affected system.

Отчет

FreeIPMI contains a stack-based buffer overflow triggered by oversized responses from a Baseboard Management Controller (BMC), potentially allowing arbitrary code execution. The severity is constrained to Moderate because the vulnerability cannot be exploited without direct administrative interaction. An attacker must possess a compromised BMC and rely on an administrator to explicitly execute FreeIPMI commands against it to trigger the vulnerable code path.

Меры по смягчению последствий

Restrict IPMI and BMC access to a dedicated, trusted management network so FreeIPMI clients cannot reach untrusted or compromised controllers. Please do not run ipmi-fru or bmc-device --read-fru against untrusted BMCs. If FRU inventory queries are not required, do not use those tools (or other libfreeipmi FRU callers) against remote management controllers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freeipmiAffected
Red Hat Enterprise Linux 6freeipmiOut of support scope
Red Hat Enterprise Linux 7freeipmiAffected
Red Hat Enterprise Linux 8freeipmiAffected
Red Hat Enterprise Linux 9freeipmiAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2528399FreeIPMI: FreeIPMI: Arbitrary code execution via stack-based buffer overflow

EPSS

Процентиль: 32%
0.00388
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

CVSS3: 9.8
nvd
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

msrc
11 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

CVSS3: 9.8
debian
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_ ...

CVSS3: 9.8
github
12 дней назад

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

EPSS

Процентиль: 32%
0.00388
Низкий

7.5 High

CVSS3