Executive brief
IBM MQ is an enterprise messaging system used to transport data between applications and systems. An authenticated attacker can exploit a heap buffer overflow vulnerability when IBM MQ processes specially crafted message distribution headers, leading to service outages or potentially gaining elevated privileges to execute arbitrary code on the messaging infrastructure.
Technical details
A heap-based buffer overflow (CWE-122) exists in IBM MQ when processing MQPUT operations with malformed distribution headers. The vulnerability requires an authenticated attacker with network access to the queue manager. An attacker can send a crafted MQPUT request to trigger the buffer overflow, resulting in denial of service or potential privilege escalation and remote code execution. Patches are available for all affected LTS and CD versions: apply cumulative security updates for versions 9.1–9.4 LTS, or upgrade to version 10.0.0.5 or later for CD/10.0 streams.
Affected products
- IBM MQ 9.1.0.0–9.1.0.37 LTS, 9.2.0.0–9.2.0.43 LTS, 9.3.0.0–9.3.0.41 LTS, 9.3.0.0–9.3.5.1 CD, 9.4.0.0–9.4.0.25 LTS, 9.4.0.0–9.4.5.1 CD, 10.0.0.0
Timeline
- 2026-09-18: disclosed: Initial publication of security bulletin
- 2026-09-18: patched: Cumulative security updates available: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26; upgrade to 10.0.0.5 for CD/10.0