Executive brief
IBM MQ for HPE NonStop is a message queuing system used in enterprise environments to manage reliable message transport. An authenticated attacker can exploit an integer overflow vulnerability in MQINQ request validation to cause service outages or gain elevated system privileges, particularly when CONNAUTH security is in use.
Technical details
The vulnerability is a heap-based buffer overflow (CWE-122) triggered by an integer overflow in MQINQ request validation within IBM MQ for HPE NonStop. The flaw exists in the MQINQ handler when CONNAUTH authentication is enabled. An attacker with valid credentials can craft a malicious MQINQ request that causes an integer overflow, leading to a heap buffer overflow. This allows the attacker to either crash the message queue service (denial of service) or execute arbitrary code with the privileges of the MQ process (privilege escalation). The vulnerability affects versions 8.1.0 through 8.1.0.40; IBM recommends upgrading to CSU 8.1.0.41 immediately. No workarounds are available.
Affected products
- IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fix available in CSU 8.1.0.41