Skip to content
Ubuntu FreeIPMI Critical Denial Of Service Buffer Overflow Vuln USN-8843

Ubuntu FreeIPMI Critical Denial Of Service Buffer Overflow Vuln USN-8843

Linuxsecurity •LinuxSecurity Advisories • September 29, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

Several security issues were fixed in FreeIPMI. Software Description: - freeipmi: in-band and out-of-band Intelligent Platform Management Interface Details: It was discovered that FreeIPMI incorrectly handled certain malformed Fujitsu SEL long-text responses, leading to a stack-based buffer overflow. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-85504) It was discovered that FreeIPMI incorrectly handled short responses when retrieving Fujitsu SEL entries, leading to a stack-based buffer over-read. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service. (CVE-2026-85505) It was discovered that FreeIPMI incorrectly handled certain Dell iDRAC and CMC IPv6 system information responses, leading to a stack-based buffer overflow. An attacker in control of a mal... Read the Full Advisory

Several security issues were fixed in FreeIPMI.

Software Description:

- freeipmi: in-band and out-of-band Intelligent Platform Management Interface

It was discovered that FreeIPMI incorrectly handled certain malformed

Fujitsu SEL long-text responses, leading to a stack-based buffer

overflow. An attacker in control of a malicious IPMI device could

possibly use this issue to cause FreeIPMI to crash, resulting in a denial

of service, or possibly execute arbitrary code. (CVE-2026-85504)

It was discovered that FreeIPMI incorrectly handled short responses when

retrieving Fujitsu SEL entries, leading to a stack-based buffer

over-read. An attacker in control of a malicious IPMI device could

possibly use this issue to cause FreeIPMI to crash, resulting in a denial

of service. (CVE-2026-85505)

It was discovered that FreeIPMI incorrectly handled certain Dell iDRAC

and CMC IPv6 system information responses, leading to a stack-based

buffer overflow. An attacker in control of a mal...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS freeipmi-tools 1.6.16-1ubuntu0.2 libfreeipmi17 1.6.16-1ubuntu0.2 Ubuntu 24.04 LTS freeipmi-tools 1.6.13-3ubuntu0.2 libfreeipmi17 1.6.13-3ubuntu0.2 Ubuntu 22.04 LTS freeipmi-tools 1.6.9-2ubuntu0.22.04.4 libfreeipmi17 1.6.9-2ubuntu0.22.04.4 Ubuntu 20.04 LTS freeipmi-tools 1.6.4-3ubuntu1.1+esm2 Available with Ubuntu Pro libfreeipmi-dev 1.6.4-3ubuntu1.1+esm2 Available with Ubuntu Pro libfreeipmi17 1.6.4-3ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS freeipmi-tools 1.4.11-1.1ubuntu4.1+esm2 Available with Ubuntu Pro libfreeipmi-dev 1.4.11-1.1ubuntu4.1+esm2 Available with Ubuntu Pro libfreeipmi16 1.4.11-1.1ubuntu4.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS freeipmi-tools 1.4.11-1.1ubuntu4.1~0.16.04.1~esm2 Available with Ubuntu Pro libfreeipmi-dev 1.4.11-1.1ubuntu4.1~0.16.04.1~esm2 Available with Ubuntu Pro libfreeipmi16 1.4.11-1.1ubuntu4.1~0.16.04.1~esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS freeipmi-tools 1.1.5-3ubuntu3.3+esm2 Available with Ubuntu Pro libfreeipmi-dev 1.1.5-3ubuntu3.3+esm2 Available with Ubuntu Pro libfreeipmi12 1.1.5-3ubuntu3.3+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2026-85504, CVE-2026-85505, CVE-2026-85506, CVE-2026-85507,

CVE-2026-85508, CVE-2026-85509

Ubuntu Security Notice USN-8843-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases