Reference data/CVE/CVE-2026-85505

CVE-2026-85505

HighReceivedScore 7.5 · CVSS v3.1Patched
Published: 4 Sept 2026, 05:17Modified: 4 Sept 2026, 05:17Source: cve@mitre.org

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

Weaknesses (CWE):CWE-125

CVSS v3.1

Current7.5HIGHcve@mitre.org

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

NetworkAV:N

Attack Complexity

LowAC:L

Privileges Required

NonePR:N

User Interaction

NoneUI:N

Scope

UnchangedS:U

Confidentiality Impact

NoneC:N

Integrity Impact

NoneI:N

Availability Impact

HighA:H

CVSS temporel

Estimation6.5

E:U/RL:O/RC:C

Temporal score updated on 4 Sept 2026, 07:36

Source: PatchCVE heuristic estimate (CISA KEV, EPSS from FIRST.org, NVD reference tags, NVD status) — not published by a CNA.

Exploit Code Maturity

UnprovenE:U

No known exploit

No known exploit: absent from CISA KEV and exploit-db, no reference tagged Exploit, SSVC reports no exploitation — Unproven

Remediation Level

Official FixRL:O

Detected in the description

Report Confidence

ConfirmedRC:C

Red Hat: product analysis published