#1146649 freeipmi: CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509

Package:
src:freeipmi
Source:
src:freeipmi
Submitter:
Salvatore Bonaccorso
Date:
2026-09-04 07:23:02 UTC
Severity:
normal
Tags:
#1146649#5
Date:
2026-09-04 07:21:49 UTC
From:
To:
Hi,

The following vulnerabilities were published for freeipmi.

CVE-2026-85504[0]:
| FreeIPMI before 1.6.19 has a stack-based buffer overflow in
| _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in
| libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed
| Fujitsu SEL long-text responses.


CVE-2026-85505[1]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-
| read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-
| oem-fujitsu.c when a BMC provides a short response, a different
| vulnerability than CVE-2026-50031 (which has different affected
| versions).


CVE-2026-85506[2]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow
| in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c
| (idrac-info subcommand to dell get-system-info).


CVE-2026-85507[3]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow
| in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c
| (cmc-info subcommand to dell get-system-info).


CVE-2026-85508[4]:
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow
| in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-
| dell.c (cmc-ipv6-info subcommand to dell get-system-info).


CVE-2026-85509[5]:
| FreeIPMI before 1.6.19 has a stack-based buffer overflow in
| _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more
| bytes than requested.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-85504
https://www.cve.org/CVERecord?id=CVE-2026-85504
[1] https://security-tracker.debian.org/tracker/CVE-2026-85505
https://www.cve.org/CVERecord?id=CVE-2026-85505
[2] https://security-tracker.debian.org/tracker/CVE-2026-85506
https://www.cve.org/CVERecord?id=CVE-2026-85506
[3] https://security-tracker.debian.org/tracker/CVE-2026-85507
https://www.cve.org/CVERecord?id=CVE-2026-85507
[4] https://security-tracker.debian.org/tracker/CVE-2026-85508
https://www.cve.org/CVERecord?id=CVE-2026-85508
[5] https://security-tracker.debian.org/tracker/CVE-2026-85509
https://www.cve.org/CVERecord?id=CVE-2026-85509
[6] https://www.openwall.com/lists/oss-security/2026/08/28/5

Regards,
Salvatore