CVE-2026-85508
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-85508 is a stack-based buffer overflow vulnerability in the ipmi-oem component of FreeIPMI before version 1.6.19. The flaw resides in the _output_dell_system_info_cmc_ipv6_info function within ipmi-oem/ipmi-oem-dell.c, triggered via the cmc-ipv6-info subcommand of the dell get-system-info command. It was disclosed on August 28, 2026 via the oss-security mailing list and published to NVD on September 4, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, oss-security).

Technical details

The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), caused by insufficient bounds checking when processing Dell CMC IPv6 system information responses in the _output_dell_system_info_cmc_ipv6_info function. An attacker can exploit this by sending a crafted IPMI response over the network that causes the function to write beyond the bounds of a stack-allocated buffer. The attack requires no authentication and no user interaction, making it exploitable remotely with low complexity. The fix was included in FreeIPMI 1.6.19, which also addressed related stack overflow issues in the idrac-info, cmc-info subcommands, and Fujitsu SEL entry handling (oss-security, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with the privileges of the ipmi-oem process, resulting in full compromise of confidentiality, integrity, and availability on the affected host. Given that IPMI interfaces are often used for out-of-band server management, exploitation could grant an attacker persistent, low-level access to physical servers, potentially enabling lateral movement across data center infrastructure. Data exposure risk is high, as the compromised process may have access to sensitive system management credentials and configuration data (GitHub Advisory, oss-security).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify hosts running FreeIPMI ipmi-oem versions prior to 1.6.19 with network-accessible IPMI interfaces (typically UDP/623 or TCP/623) using network scanners such as Nmap or Shodan.
  2. Target the vulnerable subcommand: Invoke or simulate the ipmi-oem dell get-system-info cmc-ipv6-info subcommand against a target IPMI-enabled server, or position as a malicious IPMI responder (man-in-the-middle) to return a crafted response.
  3. Craft malicious IPMI response: Construct an oversized or malformed CMC IPv6 info response payload that exceeds the bounds of the stack buffer in _output_dell_system_info_cmc_ipv6_info within ipmi-oem/ipmi-oem-dell.c.
  4. Trigger buffer overflow: Deliver the crafted payload to the vulnerable ipmi-oem process, overwriting the stack return address or control data.
  5. Achieve code execution: Redirect execution flow to attacker-controlled shellcode or a ROP chain, gaining arbitrary code execution with the privileges of the ipmi-oem process (oss-security, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous IPMI traffic (UDP/TCP port 623) from untrusted hosts; unusual IPMI response packets with oversized CMC IPv6 info fields.
  • Process: Unexpected child processes spawned by ipmi-oem; crashes or core dumps of the ipmi-oem binary indicating exploitation attempts.
  • Logs: System logs (/var/log/syslog, /var/log/messages) showing segmentation faults or abnormal termination of ipmi-oem; IPMI audit logs recording unexpected dell get-system-info cmc-ipv6-info queries from unknown sources.
  • File System: Presence of core dump files (e.g., core.*) in the working directory of ipmi-oem; unexpected new files or scripts created by the ipmi-oem process owner.

Mitigation and workarounds

Upgrade FreeIPMI to version 1.6.19 or later, which contains the fix for this stack overflow and related issues (oss-security). The patched release is available at the official GNU FTP server. As interim mitigations: restrict network access to IPMI interfaces to trusted management hosts only using firewall rules; disable Dell OEM extensions (ipmi-oem dell) if not operationally required; and implement network segmentation to isolate IPMI management networks from general-purpose networks.

Community reactions

The vulnerability was disclosed by Al Chu (Lawrence Livermore National Laboratory) via the FreeIPMI announce mailing list and forwarded to the oss-security list by Chad Dougherty, following standard responsible disclosure practices for open-source projects (oss-security). No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80886NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80885NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80884NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80883NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026
CVE-2026-80882NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management