
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85508 is a stack-based buffer overflow vulnerability in the ipmi-oem component of FreeIPMI before version 1.6.19. The flaw resides in the _output_dell_system_info_cmc_ipv6_info function within ipmi-oem/ipmi-oem-dell.c, triggered via the cmc-ipv6-info subcommand of the dell get-system-info command. It was disclosed on August 28, 2026 via the oss-security mailing list and published to NVD on September 4, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, oss-security).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), caused by insufficient bounds checking when processing Dell CMC IPv6 system information responses in the _output_dell_system_info_cmc_ipv6_info function. An attacker can exploit this by sending a crafted IPMI response over the network that causes the function to write beyond the bounds of a stack-allocated buffer. The attack requires no authentication and no user interaction, making it exploitable remotely with low complexity. The fix was included in FreeIPMI 1.6.19, which also addressed related stack overflow issues in the idrac-info, cmc-info subcommands, and Fujitsu SEL entry handling (oss-security, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with the privileges of the ipmi-oem process, resulting in full compromise of confidentiality, integrity, and availability on the affected host. Given that IPMI interfaces are often used for out-of-band server management, exploitation could grant an attacker persistent, low-level access to physical servers, potentially enabling lateral movement across data center infrastructure. Data exposure risk is high, as the compromised process may have access to sensitive system management credentials and configuration data (GitHub Advisory, oss-security).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
ipmi-oem versions prior to 1.6.19 with network-accessible IPMI interfaces (typically UDP/623 or TCP/623) using network scanners such as Nmap or Shodan.ipmi-oem dell get-system-info cmc-ipv6-info subcommand against a target IPMI-enabled server, or position as a malicious IPMI responder (man-in-the-middle) to return a crafted response._output_dell_system_info_cmc_ipv6_info within ipmi-oem/ipmi-oem-dell.c.ipmi-oem process, overwriting the stack return address or control data.ipmi-oem process (oss-security, GitHub Advisory).ipmi-oem; crashes or core dumps of the ipmi-oem binary indicating exploitation attempts./var/log/syslog, /var/log/messages) showing segmentation faults or abnormal termination of ipmi-oem; IPMI audit logs recording unexpected dell get-system-info cmc-ipv6-info queries from unknown sources.core.*) in the working directory of ipmi-oem; unexpected new files or scripts created by the ipmi-oem process owner.Upgrade FreeIPMI to version 1.6.19 or later, which contains the fix for this stack overflow and related issues (oss-security). The patched release is available at the official GNU FTP server. As interim mitigations: restrict network access to IPMI interfaces to trusted management hosts only using firewall rules; disable Dell OEM extensions (ipmi-oem dell) if not operationally required; and implement network segmentation to isolate IPMI management networks from general-purpose networks.
The vulnerability was disclosed by Al Chu (Lawrence Livermore National Laboratory) via the FreeIPMI announce mailing list and forwarded to the oss-security list by Chad Dougherty, following standard responsible disclosure practices for open-source projects (oss-security). No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."