
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85507 is a stack-based buffer overflow vulnerability in the ipmi-oem utility of FreeIPMI, specifically in the _output_dell_system_info_cmc_info function within ipmi-oem/ipmi-oem-dell.c. It is triggered via the cmc-info subcommand of the dell get-system-info command. All FreeIPMI versions prior to 1.6.19 are affected. The vulnerability was publicly disclosed on August 28, 2026 via the oss-security mailing list and formally published on September 4, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Red Hat Bugzilla).
The root cause is a stack-based buffer overflow (CWE-121 / CWE-787) in the _output_dell_system_info_cmc_info function in ipmi-oem/ipmi-oem-dell.c. When the ipmi-oem utility processes a response to the cmc-info subcommand of dell get-system-info, it writes data into a fixed-size stack buffer without adequate bounds checking, allowing an attacker-controlled IPMI response to overflow the buffer. Because the attack vector is network-based with no authentication or user interaction required, a malicious or compromised BMC/IPMI endpoint could return a crafted response that triggers the overflow. The same release notes indicate related stack overflow issues in idrac-info, cmc-ipv6-info, and Fujitsu get-sel-entry-long-text subcommands, suggesting a broader pattern of insufficient bounds checking in OEM extension parsing (oss-security, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with the privileges of the ipmi-oem process, which typically runs with elevated system privileges in out-of-band management contexts. This results in full compromise of confidentiality, integrity, and availability of the affected host. Given that IPMI management interfaces often have broad access to server hardware and firmware, exploitation could facilitate persistent access, lateral movement within management networks, or complete server takeover (Red Hat Bugzilla, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported at 0.0, reflecting low current exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
ipmi-oem utility (versions < 1.6.19) that communicate with Dell server management controllers (CMC/iDRAC) over a network-accessible IPMI interface.ipmi-oem dell get-system-info cmc-info, which initiates a query to the BMC and processes the response through the vulnerable _output_dell_system_info_cmc_info function._output_dell_system_info_cmc_info, overwriting the return address or other control data on the stack.ipmi-oem process (oss-security, GitHub Advisory).ipmi-oem (e.g., shells, network utilities); crashes or core dumps of the ipmi-oem process, potentially indicating failed exploitation attempts.ipmi-oem in system directories; unexpected new files or scripts created in directories writable by the process user./var/log/syslog, /var/log/messages) showing segmentation faults or abnormal termination of ipmi-oem; audit logs recording unusual execution of commands following ipmi-oem invocation.Upgrade FreeIPMI to version 1.6.19 or later, which includes fixes for the stack overflow in cmc-info, idrac-info, cmc-ipv6-info, and related subcommands (oss-security). The patched release is available at the official GNU FTP server. As an interim workaround, restrict network access to IPMI management interfaces using firewall rules or network segmentation, limiting IPMI traffic to trusted management VLANs only. Avoid running ipmi-oem dell get-system-info cmc-info against untrusted or potentially compromised BMC endpoints until patched (GitHub Advisory, Red Hat Bugzilla).
Red Hat has opened a tracking bug (Bug 2528396) and classified the issue as high severity, indicating it is being assessed for impact on Red Hat Enterprise Linux packages. The vulnerability was responsibly disclosed via the oss-security mailing list by Chad Dougherty, forwarding the official FreeIPMI release announcement from Al Chu at Lawrence Livermore National Laboratory. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been observed at this time (oss-security, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."