Description
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
Published: 2026-09-04
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FreeIPMI versions prior to 1.6.19 contain a stack‑based buffer over‑read flaw in the function that obtains the long text of a SEL entry for Fujitsu BMCs. When the BMC returns a short response, the implementation incorrectly copies data past the end of a stack buffer, potentially exposing sensitive internal information to the caller.

Affected Systems

The affected product is FreeIPMI from the FreeIPMI project. All releases before 1.6.19 are vulnerable, while version 1.6.19 and later contain the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating high severity. No EPSS data is available, but the flaw is in the IPMI layer, which is typically reachable from a remote host on the management network. The flaw can be exploited by an attacker that can send crafted OEM commands to the BMC; a short, malformed response allows the attacker to read beyond the intended buffer. The issue is not listed in CISA KEV, and no public exploit is currently known, but the absence of a publicly available exploit does not reduce the potential risk if an attacker can generate the required traffic.

Generated by OpenCVE AI on September 4, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FreeIPMI to version 1.6.19 or later
  • Ensure the BMC firmware is up to date to prevent short or malformed responses
  • Disable or limit the use of ipmi-oem-fujitsu SEL entry long text requests on the management network

Generated by OpenCVE AI on September 4, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Freeipmi
Freeipmi freeipmi
Vendors & Products Freeipmi
Freeipmi freeipmi

Fri, 04 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Over-read in FreeIPMI ipmi-oem-fujitsu.oem

Fri, 04 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Freeipmi Freeipmi
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T04:29:05.558Z

Reserved: 2026-09-04T04:16:05.213Z

Link: CVE-2026-85505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T05:17:16.170

Modified: 2026-09-04T05:17:16.170

Link: CVE-2026-85505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T06:00:11Z

Weaknesses