CVE-2026-85505
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-85505 is a stack-based buffer over-read vulnerability in the ipmi-oem component of FreeIPMI, specifically in the ipmi_oem_fujitsu_get_sel_entry_long_text function within ipmi-oem/ipmi-oem-fujitsu.c. The flaw is triggered when a Baseboard Management Controller (BMC) returns a shorter-than-expected response, causing the tool to read beyond the intended buffer boundary. All FreeIPMI versions before 1.6.19 are affected. It was publicly disclosed on August 28, 2026 via the oss-security mailing list and formally published on September 4, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, GitHub Advisory, Openwall).

Technical details

The root cause is an out-of-bounds read (CWE-125) in the Fujitsu OEM extension of FreeIPMI's ipmi-oem utility. When the BMC returns a response shorter than the code expects for the get-sel-entry-long-text subcommand, the function ipmi_oem_fujitsu_get_sel_entry_long_text reads past the end of the allocated stack buffer without validating the response length. This is a network-accessible vulnerability requiring no authentication or user interaction, as the attacker can influence the BMC response over the network. It is distinct from the related CVE-2026-50031, which affects different FreeIPMI versions (Openwall, Red Hat Bugzilla).

Impact

Successful exploitation results in a denial of service (DoS) condition, crashing the ipmi-oem process due to the invalid memory read. There is no confidentiality or integrity impact — the vulnerability's sole consequence is high availability impact to the affected FreeIPMI tooling. Systems relying on FreeIPMI for BMC/IPMI management tasks would lose access to those management functions during exploitation (GitHub Advisory, Red Hat Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-85505 as of the time of disclosure. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to control or spoof BMC responses, which typically implies a privileged network position or physical access to the management network (GitHub Advisory, Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify systems running FreeIPMI versions prior to 1.6.19 that use the ipmi-oem utility with Fujitsu BMC hardware, or systems where the management network is accessible.
  2. Position on management network: Gain access to the IPMI/BMC management network, either through a compromised host on that network segment or by spoofing BMC responses.
  3. Trigger malformed BMC response: Craft or intercept a BMC response to the get-sel-entry-long-text Fujitsu OEM command such that the response payload is shorter than the expected length.
  4. Induce crash: When ipmi_oem_fujitsu_get_sel_entry_long_text processes the short response, it reads beyond the stack buffer boundary, causing the ipmi-oem process to crash and resulting in a denial of service (Openwall, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Unexpected crashes or segmentation faults in ipmi-oem process logs; core dump files generated by the ipmi-oem binary.
  • Process: Abnormal termination of ipmi-oem processes, particularly when executing Fujitsu OEM get-sel-entry-long-text subcommands.
  • Network: Unusual or malformed IPMI/RMCP responses on UDP port 623 from BMC addresses; unexpected traffic patterns on the out-of-band management network.

Mitigation and workarounds

Upgrade FreeIPMI to version 1.6.19 or later, which includes fixes for the stack buffer over-read in the Fujitsu OEM SEL entry handling as well as related issues in libfreeipmi. The release was made available on August 27, 2026 and can be obtained from the official GNU FTP server. As a workaround, restrict access to the IPMI/BMC management network to trusted hosts only, limiting the ability of an attacker to influence BMC responses (Openwall, GitHub Advisory).

Community reactions

The vulnerability was disclosed by Al Chu (Lawrence Livermore National Laboratory) via the FreeIPMI announce mailing list and forwarded to the oss-security list by Chad Dougherty. Red Hat opened a high-severity bug tracking entry (Bug 2528400) shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Openwall, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80886NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80885NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80884NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80883NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80882NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management