SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85504

CRITICAL · CVSS 9.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

FreeIPMI versions prior to 1.6.19 are vulnerable to a stack-based buffer overflow due to improper handling of malformed Fujitsu SEL long-text responses in the _ipmi_sel_oem_fujitsu_get_sel_entry_long_text function. This vulnerability can lead to remote code execution, potentially allowing attackers to gain control over affected systems. Organizations using FreeIPMI should prioritize updating to the latest version to mitigate this critical risk.

CVE
CVE-2026-85504
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%

Original NVD Description

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.