FreeIPMI versions before 1.6.19 contain a critical stack-based buffer overflow, tracked as CVE-2026-85504, in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text. An attacker can reportedly trigger the flaw by supplying malformed Fujitsu System Event Log (SEL) long-text responses; the issue carries a CVSS v3.1 score of 9.8 and requires neither privileges nor user interaction.
FreeIPMI 1.6.19 remediates the Fujitsu SEL issue alongside other potential stack overflows found through code analysis, including flaws in Dell-focused ipmi-oem system-information functionality and libfreeipmi. The release also includes numerous reliability, parsing, portability, monitoring, and memory-management corrections. Organizations using FreeIPMI should upgrade to version 1.6.19 or later.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-85504 was published for a critical remotely exploitable stack-based buffer overflow in FreeIPMI versions before 1.6.19. Malformed Fujitsu SEL long-text responses can trigger the flaw in `_ipmi_sel_oem_fujitsu_get_sel_entry_long_text`; upgrading to 1.6.19 or later remediates it.
Chad Dougherty forwarded Al Chu's FreeIPMI 1.6.19 release announcement to the oss-security mailing list, advising users to upgrade for the buffer-overflow fixes.
FreeIPMI 1.6.19 was released, fixing potential stack buffer overflows found through code analysis, including Fujitsu long SEL-entry handling in ipmi-oem and libfreeipmi. The release also addressed potential overflows in Dell get-system-info subcommands.
The FreeIPMI 1.6.19 fixes were assigned six CVEs: CVE-2026-85504 through CVE-2026-85509. In addition to the Fujitsu SEL overflow tracked as CVE-2026-85504, the release addresses potential Dell OEM command and libfreeipmi Fujitsu SEL-entry stack overflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecvefeed.io
Open sourcetenable.com
Open sourcesavannah.gnu.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.