Description
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
Published: 2026-09-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

FreeIPMI versions prior to 1.6.19 contain a stack‑based buffer over‑read flaw in the function that obtains the long text of a SEL entry for Fujitsu BMCs. When the BMC returns a short response, the implementation incorrectly copies data past the end of a stack buffer, potentially exposing sensitive internal information to the caller.

Affected Systems

The affected product is FreeIPMI from the FreeIPMI project. All releases before 1.6.19 are vulnerable, while version 1.6.19 and later contain the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating high severity. No EPSS data is available, but the flaw is in the IPMI layer, which is typically reachable from a remote host on the management network. The flaw can be exploited by an attacker that can send crafted OEM commands to the BMC; a short, malformed response allows the attacker to read beyond the intended buffer. The issue is not listed in CISA KEV, and no public exploit is currently known, but the absence of a publicly available exploit does not reduce the potential risk if an attacker can generate the required traffic.

Generated by OpenCVE AI on September 4, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FreeIPMI to version 1.6.19 or later
  • Ensure the BMC firmware is up to date to prevent short or malformed responses
  • Disable or limit the use of ipmi-oem-fujitsu SEL entry long text requests on the management network

Generated by OpenCVE AI on September 4, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Over-read in FreeIPMI ipmi-oem-fujitsu.oem FreeIPMI: FreeIPMI: Denial of Service via stack-based buffer over-read in ipmi-oem
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 04 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Freeipmi
Freeipmi freeipmi
Vendors & Products Freeipmi
Freeipmi freeipmi

Fri, 04 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Over-read in FreeIPMI ipmi-oem-fujitsu.oem

Fri, 04 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Freeipmi Freeipmi
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-08T14:38:23.147Z

Reserved: 2026-09-04T04:16:05.213Z

Link: CVE-2026-85505

cve-icon Vulnrichment

Updated: 2026-09-08T14:38:19.293Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T05:17:16.170

Modified: 2026-09-09T16:03:22.897

Link: CVE-2026-85505

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-04T04:16:05Z

Links: CVE-2026-85505 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T06:00:11Z

Weaknesses