GPU VulnDB

Database/Firmware, BMC & network fabric

FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responses

CVSS 9.8CVE-2026-85504Firmware, BMC & network fabriccurated

Impact

_ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi overflows a stack buffer when a Fujitsu iRMC returns a malformed long-text system event log response. SEL collection is the routine, often automated, path on a fleet - ipmi-sel runs from monitoring and from failure triage on nodes that just fell over - so the code sits in a library that management hosts point at every BMC they own. A BMC that has already been compromised, or an attacker who can answer for one on the management network, can turn a log-collection run into memory corruption on the collector. Distinct from the Dell OEM overflows fixed in the same release: different subsystem, different parser, different trigger.

Who can reach it

Whoever controls the responses of the BMC whose SEL is being read - a compromised Fujitsu iRMC, or an attacker positioned on the management VLAN able to forge IPMI responses. Requires that SEL reading actually be performed against that endpoint; no authentication to the management host is needed.

What to do

Upgrade FreeIPMI to 1.6.19 or take the distro backport. It is a library and CLI package update on management and monitoring hosts - restart whatever long-lived collector links libfreeipmi, but no node drain, reboot or firmware flash. If any monitoring daemon on the management host loads it in-process, that process needs restarting to pick up the new library.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.