Reference data/CVE/CVE-2026-85506

CVE-2026-85506

CriticalReceivedScore 9.8 · CVSS v3.1
Published: 4 Sept 2026, 05:17Modified: 4 Sept 2026, 05:17Source: cve@mitre.org

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

Weaknesses (CWE):CWE-121

CVSS v3.1

Current9.8CRITICALcve@mitre.org

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

NetworkAV:N

Attack Complexity

LowAC:L

Privileges Required

NonePR:N

User Interaction

NoneUI:N

Scope

UnchangedS:U

Confidentiality Impact

HighC:H

Integrity Impact

HighI:H

Availability Impact

HighA:H

CVSS temporel

Estimation8.7

E:U/RL:W/RC:C

Temporal score updated on 4 Sept 2026, 07:36

Source: PatchCVE heuristic estimate (CISA KEV, EPSS from FIRST.org, NVD reference tags, NVD status) — not published by a CNA.

Exploit Code Maturity

UnprovenE:U

No known exploit

No known exploit: absent from CISA KEV and exploit-db, no reference tagged Exploit, SSVC reports no exploitation — Unproven

Remediation Level

WorkaroundRL:W

Red Hat: workaround available, no official fix published

Report Confidence

ConfirmedRC:C

Red Hat: product analysis published