CVE-2026-10575
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | MQ | 9.1.0.0 <= 9.1.0.37 LTS | affected |
| IBM | MQ | 9.2.0.0 <= 9.2.0.43 LTS | affected |
| IBM | MQ | 9.3.0.0 <= 9.3.0.41 LTS | affected |
| IBM | MQ | 9.3.0.0 <= 9.3.5.1 CD | affected |
| IBM | MQ | 9.4.0.0 <= 9.4.0.25 LTS | affected |
| IBM | MQ | 9.4.0.0 <= 9.4.5.1 CD | affected |
| IBM | MQ | 10.0.0.0 | affected |
Weaknesses
- CWE-122: CWE-122 Heap-based Buffer Overflow
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.