Description
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
Published: 2026-09-04
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the ipmi-oem component of FreeIPMI, affecting the idrac-info subcommand used to retrieve Dell system information. This flaw can allow an attacker to execute arbitrary code with the privileges of the ipmi-oem process. The vulnerability is identified as CWE-121 and carries a CVSS score of 9.8, indicating extreme severity and the potential for full system compromise once exploited.

Affected Systems

The flaw is present in FreeIPMI versions prior to 1.6.19. Systems running any version of the FreeIPMI package before 1.6.19 are vulnerable. This includes installations that rely on the ipmi-oem-dell interface for Dell server management.

Risk and Exploitability

Given the lack of an EPSS score, the precise exploitation likelihood is uncertain, but the high CVSS rating indicates that the vulnerability would be attractive to malicious actors. The attack vector is inferred as either remote over network‑exposed IPMI interfaces or local through privileged user access to the ipmi-oem command, as the overflow occurs when parsing the idrac-info subcommand. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate attention.

Generated by OpenCVE AI on September 4, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to FreeIPMI 1.6.19 or later
  • Disable or remove the idrac-info subcommand if it is not required for operations
  • Restrict network access to the IPMI interface to trusted hosts and enforce least‑privilege access controls

Generated by OpenCVE AI on September 4, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Freeipmi
Freeipmi freeipmi
Vendors & Products Freeipmi
Freeipmi freeipmi

Fri, 04 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Freeipmi Freeipmi
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T04:17:33.524Z

Reserved: 2026-09-04T04:17:33.177Z

Link: CVE-2026-85506

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T05:17:16.290

Modified: 2026-09-04T05:17:16.290

Link: CVE-2026-85506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T06:00:11Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow