FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC r...

Date Sep 3, 2026
Type Patch Tuesday
Signal Critical vendor advisory
Vendor / Product Microsoft ยท Mariner
CVE CVE-2026-85509
Critical vendor advisory CVE-2026-85509

Summary

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. Published in September 2026 Early Security Updates.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates. EPSS percentile: 32%.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-85509. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 32%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.