Hi,
The following vulnerabilities were published for freeipmi.
CVE-2026-85504[0]:
| FreeIPMI before 1.6.19 has a stack-based buffer overflow in
| _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in
| libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed
| Fujitsu SEL long-text responses.
CVE-2026-85505[1]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-
| read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-
| oem-fujitsu.c when a BMC provides a short response, a different
| vulnerability than CVE-2026-50031 (which has different affected
| versions).
CVE-2026-85506[2]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow
| in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c
| (idrac-info subcommand to dell get-system-info).
CVE-2026-85507[3]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow
| in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c
| (cmc-info subcommand to dell get-system-info).
CVE-2026-85508[4]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow
| in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-
| dell.c (cmc-ipv6-info subcommand to dell get-system-info).
CVE-2026-85509[5]:
| FreeIPMI before 1.6.19 has a stack-based buffer overflow in
| _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more
| bytes than requested.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-85504
https://www.cve.org/CVERecord?id=CVE-2026-85504
[1] https://security-tracker.debian.org/tracker/CVE-2026-85505
https://www.cve.org/CVERecord?id=CVE-2026-85505
[2] https://security-tracker.debian.org/tracker/CVE-2026-85506
https://www.cve.org/CVERecord?id=CVE-2026-85506
[3] https://security-tracker.debian.org/tracker/CVE-2026-85507
https://www.cve.org/CVERecord?id=CVE-2026-85507
[4] https://security-tracker.debian.org/tracker/CVE-2026-85508
https://www.cve.org/CVERecord?id=CVE-2026-85508
[5] https://security-tracker.debian.org/tracker/CVE-2026-85509
https://www.cve.org/CVERecord?id=CVE-2026-85509
[6] https://www.openwall.com/lists/oss-security/2026/08/28/5
Regards,
Salvatore