Executive brief
IBM MQ is a message queuing system used by enterprises to route and manage business-critical communications between applications. A heap buffer overflow vulnerability in the cluster repository manager allows authenticated attackers with cluster access to crash the queue manager (denial of service) or execute arbitrary code with queue manager privileges. This could lead to data theft, system compromise, or operational outage.
Technical details
The vulnerability is a heap buffer overflow caused by improper validation of cluster command message lengths in the queue manager's cluster repository manager component. An authenticated attacker with cluster network access can send a maliciously crafted cluster command message to trigger the overflow, leading to denial of service or code execution. Patches are available for all supported versions.
Affected products
- IBM MQ 9.1.0.0 to 9.1.0.37 LTS, 9.2.0.0 to 9.2.0.43 LTS, 9.3.0.0 to 9.3.0.41 LTS, 9.3.0.0 to 9.3.5.1 CD, 9.4.0.0 to 9.4.0.25 LTS, 9.4.0.0 to 9.4.5.1 CD, 10.0.0.0
Timeline
- 2026-09-14: disclosed: IBM Security Bulletin published
- 2026-09: patched: Fixes available: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, 10.0.0.5