Back Linuxsecurity Ubuntu FreeIPMI Critical Denial Of Service Buffer Overflow Vuln USN-8843
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
Several security issues were fixed in FreeIPMI. Software Description: - freeipmi: in-band and out-of-band Intelligent Platform Management Interface Details: It was discovered that FreeIPMI incorrectly handled certain malformed Fujitsu SEL long-text responses, leading to a stack-based buffer overflow. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-85504) It was discovered that FreeIPMI incorrectly handled short responses when retrieving Fujitsu SEL entries, leading to a stack-based buffer over-read. An attacker in control of a malicious IPMI device could possibly use this issue to cause FreeIPMI to crash, resulting in a denial of service. (CVE-2026-85505) It was discovered that FreeIPMI incorrectly handled certain Dell iDRAC and CMC IPv6 system information responses, leading to a stack-based buffer overflow. An attacker in control of a mal... Read the Full Advisory
Several security issues were fixed in FreeIPMI.
Software Description:
- freeipmi: in-band and out-of-band Intelligent Platform Management Interface
It was discovered that FreeIPMI incorrectly handled certain malformed
Fujitsu SEL long-text responses, leading to a stack-based buffer
overflow. An attacker in control of a malicious IPMI device could
possibly use this issue to cause FreeIPMI to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2026-85504)
It was discovered that FreeIPMI incorrectly handled short responses when
retrieving Fujitsu SEL entries, leading to a stack-based buffer
over-read. An attacker in control of a malicious IPMI device could
possibly use this issue to cause FreeIPMI to crash, resulting in a denial
of service. (CVE-2026-85505)
It was discovered that FreeIPMI incorrectly handled certain Dell iDRAC
and CMC IPv6 system information responses, leading to a stack-based
buffer overflow. An attacker in control of a mal...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS freeipmi-tools 1.6.16-1ubuntu0.2 libfreeipmi17 1.6.16-1ubuntu0.2 Ubuntu 24.04 LTS freeipmi-tools 1.6.13-3ubuntu0.2 libfreeipmi17 1.6.13-3ubuntu0.2 Ubuntu 22.04 LTS freeipmi-tools 1.6.9-2ubuntu0.22.04.4 libfreeipmi17 1.6.9-2ubuntu0.22.04.4 Ubuntu 20.04 LTS freeipmi-tools 1.6.4-3ubuntu1.1+esm2 Available with Ubuntu Pro libfreeipmi-dev 1.6.4-3ubuntu1.1+esm2 Available with Ubuntu Pro libfreeipmi17 1.6.4-3ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS freeipmi-tools 1.4.11-1.1ubuntu4.1+esm2 Available with Ubuntu Pro libfreeipmi-dev 1.4.11-1.1ubuntu4.1+esm2 Available with Ubuntu Pro libfreeipmi16 1.4.11-1.1ubuntu4.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS freeipmi-tools 1.4.11-1.1ubuntu4.1~0.16.04.1~esm2 Available with Ubuntu Pro libfreeipmi-dev 1.4.11-1.1ubuntu4.1~0.16.04.1~esm2 Available with Ubuntu Pro libfreeipmi16 1.4.11-1.1ubuntu4.1~0.16.04.1~esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS freeipmi-tools 1.1.5-3ubuntu3.3+esm2 Available with Ubuntu Pro libfreeipmi-dev 1.1.5-3ubuntu3.3+esm2 Available with Ubuntu Pro libfreeipmi12 1.1.5-3ubuntu3.3+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
CVE-2026-85504, CVE-2026-85505, CVE-2026-85506, CVE-2026-85507,
CVE-2026-85508, CVE-2026-85509
Ubuntu Security Notice USN-8843-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
