
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85505 is a stack-based buffer over-read vulnerability in the ipmi-oem component of FreeIPMI, specifically in the ipmi_oem_fujitsu_get_sel_entry_long_text function within ipmi-oem/ipmi-oem-fujitsu.c. The flaw is triggered when a Baseboard Management Controller (BMC) returns a shorter-than-expected response, causing the tool to read beyond the intended buffer boundary. All FreeIPMI versions before 1.6.19 are affected. It was publicly disclosed on August 28, 2026 via the oss-security mailing list and formally published on September 4, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, GitHub Advisory, Openwall).
The root cause is an out-of-bounds read (CWE-125) in the Fujitsu OEM extension of FreeIPMI's ipmi-oem utility. When the BMC returns a response shorter than the code expects for the get-sel-entry-long-text subcommand, the function ipmi_oem_fujitsu_get_sel_entry_long_text reads past the end of the allocated stack buffer without validating the response length. This is a network-accessible vulnerability requiring no authentication or user interaction, as the attacker can influence the BMC response over the network. It is distinct from the related CVE-2026-50031, which affects different FreeIPMI versions (Openwall, Red Hat Bugzilla).
Successful exploitation results in a denial of service (DoS) condition, crashing the ipmi-oem process due to the invalid memory read. There is no confidentiality or integrity impact — the vulnerability's sole consequence is high availability impact to the affected FreeIPMI tooling. Systems relying on FreeIPMI for BMC/IPMI management tasks would lose access to those management functions during exploitation (GitHub Advisory, Red Hat Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-85505 as of the time of disclosure. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to control or spoof BMC responses, which typically implies a privileged network position or physical access to the management network (GitHub Advisory, Red Hat Advisory).
ipmi-oem utility with Fujitsu BMC hardware, or systems where the management network is accessible.get-sel-entry-long-text Fujitsu OEM command such that the response payload is shorter than the expected length.ipmi_oem_fujitsu_get_sel_entry_long_text processes the short response, it reads beyond the stack buffer boundary, causing the ipmi-oem process to crash and resulting in a denial of service (Openwall, Red Hat Bugzilla).ipmi-oem process logs; core dump files generated by the ipmi-oem binary.ipmi-oem processes, particularly when executing Fujitsu OEM get-sel-entry-long-text subcommands.Upgrade FreeIPMI to version 1.6.19 or later, which includes fixes for the stack buffer over-read in the Fujitsu OEM SEL entry handling as well as related issues in libfreeipmi. The release was made available on August 27, 2026 and can be obtained from the official GNU FTP server. As a workaround, restrict access to the IPMI/BMC management network to trusted hosts only, limiting the ability of an attacker to influence BMC responses (Openwall, GitHub Advisory).
The vulnerability was disclosed by Al Chu (Lawrence Livermore National Laboratory) via the FreeIPMI announce mailing list and forwarded to the oss-security list by Chad Dougherty. Red Hat opened a high-severity bug tracking entry (Bug 2528400) shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Openwall, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."