ZeroHour
oss-securitypublished ()ingested

Re: Fwd: [Freeipmi-announce] FreeIPMI 1.6.19 Released

AI summary · glm-5.3-flash

FreeIPMI 1.6.19 fixes multiple issues, six of which received CVEs CVE-2026-85504 through CVE-2026-85509.

Salvatore Bonaccorso forwarded the FreeIPMI 1.6.19 release announcement on oss-security, noting that six of the fixed issues received CVE identifiers: CVE-2026-85504, CVE-2026-85505, CVE-2026-85506, CVE-2026-85507, CVE-2026-85508 and CVE-2026-85509. FreeIPMI is an IPMI monitoring and management tool for Linux. No exploitation or severity detail is given.

  • FreeIPMI 1.6.19 released with fixes
  • Six CVEs assigned: CVE-2026-85504 to CVE-2026-85509
  • FreeIPMI is a niche IPMI management toolchain
  • No exploitation reported
VendorsFreeIPMI
ProductsFreeIPMI

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-85504
Stack-based buffer overflow in FreeIPMI via malformed Fujitsu iRMC SEL responses

FreeIPMI versions before 1.6.19 contain a stack-based buffer overflow (CWE-121) in the function _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c, which decodes Fujitsu iRMC OEM System Event Log (SEL) entries into long text descriptions. The flaw is triggered when FreeIPMI processes a malformed or oversized SEL long-text response supplied by a Fujitsu iRMC BMC, for example when the tool queries a compromised or spoofed BMC on the management network. With a CVSS 3.1 score of 9.8 (network vector, no privileges or user interaction required), a successful attack can compromise confidentiality, integrity, and availability, most plausibly through a crash or code execution in the process parsing the response. Anyone running FreeIPMI prior to 1.6.19 and using it to manage or monitor Fujitsu PRIMERGY servers with iRMC controllers is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates a 0.4% probability of exploitation within 30 days (32nd percentile).

Do: Upgrade to FreeIPMI 1.6.19 or later, or install a distribution security update with the fix backported. Until patched, avoid running SEL decoding/queries (e.g., ipmi-sel) against Fujitsu iRMC BMCs and restrict the IPMI management network (UDP 623) to trusted hosts. Audit which hosts have FreeIPMI installed and whether they are used to monitor Fujitsu PRIMERGY/iRMC hardware.

9.8<1%
  • GNU FreeIPMI project FreeIPMI (Fujitsu iRMC SEL long-text decoding path) all versions before 1.6.19
largeon the order of tens of thousands of management/monitoring hosts
CVE-2026-85505
Stack buffer over-read in FreeIPMI ipmi-oem Fujitsu SEL handling (fixed in 1.6.19)

CVE-2026-85505 is a stack-based buffer over-read (CWE-125) in the ipmi-oem utility of FreeIPMI, located in the function ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c. It is triggered when the tool issues a Fujitsu OEM SEL (system event log) long-text query and the BMC returns a response shorter than expected, causing the client to read past the end of a stack buffer. An attacker who controls or compromises the BMC, or who can tamper with BMC responses, can crash the ipmi-oem client process; per the CVSS 3.1 score only availability is impacted (C:N/I:N/A:H), so this is a denial-of-service issue rather than code execution or data exposure. Affected users are administrators running FreeIPMI versions before 1.6.19 who invoke the Fujitsu OEM commands in ipmi-oem; this flaw is distinct from CVE-2026-50031, which affects different versions of the software. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts exploitation probability in the next 30 days at about 0.3%, so no exploitation is currently known.

Do: Upgrade to FreeIPMI 1.6.19, or install a distribution package that includes that release, and verify the installed version via your package manager. As an interim mitigation, avoid running ipmi-oem Fujitsu SEL long-text queries against BMCs you do not fully trust and keep BMC access restricted to management networks. No public PoC or in-the-wild exploitation is known, so patching can follow normal maintenance cycles, prioritizing hosts that routinely query Fujitsu BMCs.

7.5<1%
  • FreeIPMI (GNU FreeIPMI project) ipmi-oem (Fujitsu OEM SEL long-text handling) all FreeIPMI versions before 1.6.19
nicheunknown; at most on the order of tens of thousands of hosts
CVE-2026-85506
Stack-Based Buffer Overflow in FreeIPMI ipmi-oem Dell iDRAC Command

FreeIPMI before 1.6.19 contains a stack-based buffer overflow (CWE-121) in the function _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c, the code that handles Dell OEM IPMI commands. The flaw is triggered when a user runs the 'idrac-info' subcommand of 'ipmi-oem dell get-system-info' against a Dell iDRAC/BMC, causing oversized data handled by that code path to overflow a stack buffer. A successful attack could crash the ipmi-oem tool or potentially allow arbitrary code execution with the privileges of the user running it (CVSS 9.8 critical, network vector, high confidentiality/integrity/availability impact). Anyone running a FreeIPMI release prior to 1.6.19 and using its Dell OEM commands against Dell iDRAC controllers is affected. No public proof-of-concept is known, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.4%, so no exploitation has been reported yet.

Do: Upgrade to FreeIPMI 1.6.19 or later, which fixes the overflow in ipmi-oem-dell.c. Until upgraded, avoid running 'ipmi-oem dell get-system-info idrac-info' against Dell iDRAC/BMC endpoints, particularly ones that are not fully trusted. Check installed FreeIPMI versions via your package manager and prioritize hosts where the tool is run interactively or by automation against Dell hardware.

9.8<1%
  • GNU FreeIPMI project FreeIPMI (ipmi-oem utility, Dell OEM get-system-info/idrac-info command) all versions before 1.6.19
moderateon the order of 10,000-100,000 installations worldwide (no published install counts)
CVE-2026-85507
Stack-based buffer overflow in FreeIPMI ipmi-oem Dell cmc-info command

FreeIPMI versions before 1.6.19 contain a stack-based buffer overflow (CWE-121) in the function _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c. The flaw is triggered when the ipmi-oem tool runs the 'dell get-system-info cmc-info' subcommand and parses the Chassis Management Controller (CMC) information returned by a Dell BMC, so an attacker who controls or can spoof the BMC's response (for example via a compromised or MITM'd management controller) could overflow the stack buffer in the tool. Successful exploitation could lead to arbitrary code execution in the context of the user running ipmi-oem, or at minimum a crash, consistent with the critical CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N, high impact on confidentiality, integrity, and availability). Administrators and operators who use FreeIPMI to manage Dell PowerEdge chassis and servers are affected; deployments of other vendors' hardware using the Dell OEM subcommand path are not implicated by this specific code path. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days, so no exploitation is known.

Do: Upgrade to FreeIPMI 1.6.19 or later, which fixes the overflow in _output_dell_system_info_cmc_info. As an interim mitigation, avoid running 'ipmi-oem dell get-system-info cmc-info' against BMCs you do not trust and restrict access to IPMI/BMC management networks. Verify the installed FreeIPMI version via your package manager and prioritize hosts that routinely run Dell OEM queries against shared or remotely reachable management controllers.

9.8<1%
  • GNU FreeIPMI project FreeIPMI (ipmi-oem, Dell OEM get-system-info cmc-info) all versions before 1.6.19
CVE-2026-85508
Stack-based buffer overflow in FreeIPMI ipmi-oem Dell CMC IPv6 info handling

FreeIPMI before 1.6.19 contains a stack-based buffer overflow (CWE-121) in the function _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c, reached via the 'cmc-ipv6-info' subcommand of 'ipmi-oem dell get-system-info'. The flaw is triggered when the ipmi-oem client parses a response from a Dell CMC/iDRAC-style BMC whose IPv6 info data is longer than the fixed stack buffer, so an attacker who controls a BMC or can spoof/intercept BMC responses on the management network can overflow the stack of the client process. Successful exploitation can crash ipmi-oem or execute arbitrary code with the privileges of the user running the tool, consistent with the CVSS 9.8 network-vector rating. Affected users are those running FreeIPMI older than 1.6.19 and querying Dell system information with this specific OEM subcommand, typically administrators in datacenter, HPC, or out-of-band management environments. There is currently no public PoC, no CISA KEV listing, and a low EPSS score (0.4% in 30 days), with no reports of in-the-wild exploitation.

Do: Upgrade to FreeIPMI 1.6.19 or later, which fixes the overflow in ipmi-oem/ipmi-oem-dell.c. Until then, avoid running 'ipmi-oem dell get-system-info ... cmc-ipv6-info' against BMCs you do not fully trust, and restrict access to IPMI/BMC management networks to trusted administrators to prevent spoofed BMC responses.

9.8<1%
  • FreeIPMI (GNU FreeIPMI project) FreeIPMI ipmi-oem (dell get-system-info cmc-ipv6-info) before 1.6.19
nichelikely tens of thousands of FreeIPMI installations at most, with only a small subset using the affected Dell CMC IPv6-info subcommand (estimate; no public…
CVE-2026-85509
Stack Buffer Overflow in FreeIPMI FRU Parsing via Oversized BMC Responses

FreeIPMI before 1.6.19 contains a stack-based buffer overflow (CWE-121) in the _read_fru_data function in libfreeipmi/fru/ipmi-fru.c, the code that parses Field Replaceable Unit (FRU) inventory data read from a server's BMC. The flaw is triggered when a BMC returns more bytes than were requested in the FRU read, overrunning a fixed-size stack buffer, so exploitation requires control of the BMC side, e.g. a compromised or malicious BMC or an attacker in the path of an out-of-band (IPMI LAN) session. A successful attack can crash the FreeIPMI tool or monitoring service and, as a stack overflow, may allow arbitrary code execution with the privileges of the process, which typically runs privileged for in-band hardware monitoring; CVSS 3.1 rates it 9.8 (Critical). Any deployment running FreeIPMI prior to 1.6.19 is affected, including installations from major Linux distribution packages and HPC or datacenter node-monitoring stacks. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

Do: Upgrade FreeIPMI to 1.6.19 or later, or install vendor/distro security backports as they become available, prioritizing management and monitoring hosts where FreeIPMI runs privileged. Inventory which systems have FreeIPMI installed and check the reported version before and after patching. Because the bug is triggered by BMC responses, keeping BMC firmware current and restricting IPMI (especially remote LAN) access to trusted parties reduces the likelihood that an oversized FRU response can be delivered.

9.8<1%
  • GNU FreeIPMI project FreeIPMI all versions before 1.6.19
large≈100,000+ server/cluster installations (rough order-of-magnitude estimate)
Full article

Posted by Salvatore Bonaccorso on Sep 05 Hi, FTR, some of the fixed issues got CVEs assigned, they are: CVE-2026-85504, CVE-2026-85505, CVE-2026-85506, CVE-2026-85507, CVE-2026-85508 and CVE-2026-85509. Regards, Salvatore

This source does not provide full text. Read it at seclists.org.