Source: freeipmi Version: 1.6.18-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for freeipmi. CVE-2026-85504[0]: | FreeIPMI before 1.6.19 has a stack-based buffer overflow in | _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in | libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed | Fujitsu SEL long-text responses. CVE-2026-85505[1]: | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over- | read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi- | oem-fujitsu.c when a BMC provides a short response, a different | vulnerability than CVE-2026-50031 (which has different affected | versions). CVE-2026-85506[2]: | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow | in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c | (idrac-info subcommand to dell get-system-info). CVE-2026-85507[3]: | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow | in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c | (cmc-info subcommand to dell get-system-info). CVE-2026-85508[4]: | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow | in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem- | dell.c (cmc-ipv6-info subcommand to dell get-system-info). CVE-2026-85509[5]: | FreeIPMI before 1.6.19 has a stack-based buffer overflow in | _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more | bytes than requested. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-85504 https://www.cve.org/CVERecord?id=CVE-2026-85504 [1] https://security-tracker.debian.org/tracker/CVE-2026-85505 https://www.cve.org/CVERecord?id=CVE-2026-85505 [2] https://security-tracker.debian.org/tracker/CVE-2026-85506 https://www.cve.org/CVERecord?id=CVE-2026-85506 [3] https://security-tracker.debian.org/tracker/CVE-2026-85507 https://www.cve.org/CVERecord?id=CVE-2026-85507 [4] https://security-tracker.debian.org/tracker/CVE-2026-85508 https://www.cve.org/CVERecord?id=CVE-2026-85508 [5] https://security-tracker.debian.org/tracker/CVE-2026-85509 https://www.cve.org/CVERecord?id=CVE-2026-85509 [6] https://www.openwall.com/lists/oss-security/2026/08/28/5 Regards, Salvatore

