CVE-2026-85505
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
CVSS v3.1
Current7.5HIGHcve@mitre.orgAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NetworkAV:N
Attack Complexity
LowAC:L
Privileges Required
NonePR:N
User Interaction
NoneUI:N
Scope
UnchangedS:U
Confidentiality Impact
NoneC:N
Integrity Impact
NoneI:N
Availability Impact
HighA:H
CVSS temporel
Estimation6.5E:U/RL:O/RC:C
Temporal score updated on 4 Sept 2026, 07:36
Source: PatchCVE heuristic estimate (CISA KEV, EPSS from FIRST.org, NVD reference tags, NVD status) — not published by a CNA.
Exploit Code Maturity
UnprovenE:U
No known exploit
No known exploit: absent from CISA KEV and exploit-db, no reference tagged Exploit, SSVC reports no exploitation — Unproven
Remediation Level
Official FixRL:O
Detected in the description
Report Confidence
ConfirmedRC:C
Red Hat: product analysis published
References — 6
- https://nvd.nist.gov/vuln/detail/CVE-2026-85505(nvd.nist.gov)Official source
- https://ftp.gnu.org/gnu/freeipmi/freeipmi-1.6.19.tar.gz(cve@mitre.org)
- https://www.gnu.org/software/freeipmi/(cve@mitre.org)
- https://www.openwall.com/lists/oss-security/2026/08/28/5(cve@mitre.org)
- https://access.redhat.com/security/cve/cve-2026-85505(access.redhat.com)Official source
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70883(euvd.enisa.europa.eu)Official source