CVE-2026-85507
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-85507 is a stack-based buffer overflow vulnerability in the ipmi-oem utility of FreeIPMI, specifically in the _output_dell_system_info_cmc_info function within ipmi-oem/ipmi-oem-dell.c. It is triggered via the cmc-info subcommand of the dell get-system-info command. All FreeIPMI versions prior to 1.6.19 are affected. The vulnerability was publicly disclosed on August 28, 2026 via the oss-security mailing list and formally published on September 4, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is a stack-based buffer overflow (CWE-121 / CWE-787) in the _output_dell_system_info_cmc_info function in ipmi-oem/ipmi-oem-dell.c. When the ipmi-oem utility processes a response to the cmc-info subcommand of dell get-system-info, it writes data into a fixed-size stack buffer without adequate bounds checking, allowing an attacker-controlled IPMI response to overflow the buffer. Because the attack vector is network-based with no authentication or user interaction required, a malicious or compromised BMC/IPMI endpoint could return a crafted response that triggers the overflow. The same release notes indicate related stack overflow issues in idrac-info, cmc-ipv6-info, and Fujitsu get-sel-entry-long-text subcommands, suggesting a broader pattern of insufficient bounds checking in OEM extension parsing (oss-security, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with the privileges of the ipmi-oem process, which typically runs with elevated system privileges in out-of-band management contexts. This results in full compromise of confidentiality, integrity, and availability of the affected host. Given that IPMI management interfaces often have broad access to server hardware and firmware, exploitation could facilitate persistent access, lateral movement within management networks, or complete server takeover (Red Hat Bugzilla, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported at 0.0, reflecting low current exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify hosts running FreeIPMI's ipmi-oem utility (versions < 1.6.19) that communicate with Dell server management controllers (CMC/iDRAC) over a network-accessible IPMI interface.
  2. Position for man-in-the-middle or rogue BMC: Since the overflow is triggered by a crafted IPMI response, the attacker must either control a rogue BMC/IPMI endpoint, perform a man-in-the-middle attack on the IPMI management network, or compromise a Dell CMC/iDRAC device that the target queries.
  3. Trigger the vulnerable command: Cause or wait for the target system to execute ipmi-oem dell get-system-info cmc-info, which initiates a query to the BMC and processes the response through the vulnerable _output_dell_system_info_cmc_info function.
  4. Deliver crafted response: Return an oversized or malformed IPMI response payload that overflows the fixed-size stack buffer in _output_dell_system_info_cmc_info, overwriting the return address or other control data on the stack.
  5. Achieve code execution: With control of the instruction pointer, redirect execution to attacker-controlled shellcode or a ROP chain, gaining arbitrary code execution with the privileges of the ipmi-oem process (oss-security, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous IPMI traffic (UDP/623 or TCP/623) from unknown sources to management interfaces; unusual IPMI response packets with abnormally large payloads directed at hosts running FreeIPMI.
  • Process: Unexpected child processes spawned by ipmi-oem (e.g., shells, network utilities); crashes or core dumps of the ipmi-oem process, potentially indicating failed exploitation attempts.
  • File System: Presence of core dump files from ipmi-oem in system directories; unexpected new files or scripts created in directories writable by the process user.
  • Logs: System logs (/var/log/syslog, /var/log/messages) showing segmentation faults or abnormal termination of ipmi-oem; audit logs recording unusual execution of commands following ipmi-oem invocation.

Mitigation and workarounds

Upgrade FreeIPMI to version 1.6.19 or later, which includes fixes for the stack overflow in cmc-info, idrac-info, cmc-ipv6-info, and related subcommands (oss-security). The patched release is available at the official GNU FTP server. As an interim workaround, restrict network access to IPMI management interfaces using firewall rules or network segmentation, limiting IPMI traffic to trusted management VLANs only. Avoid running ipmi-oem dell get-system-info cmc-info against untrusted or potentially compromised BMC endpoints until patched (GitHub Advisory, Red Hat Bugzilla).

Community reactions

Red Hat has opened a tracking bug (Bug 2528396) and classified the issue as high severity, indicating it is being assessed for impact on Red Hat Enterprise Linux packages. The vulnerability was responsibly disclosed via the oss-security mailing list by Chad Dougherty, forwarding the official FreeIPMI release announcement from Al Chu at Lawrence Livermore National Laboratory. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been observed at this time (oss-security, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80886NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80885NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80884NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80883NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80882NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management