Executive brief
IBM MQ for HPE NonStop is a message queuing middleware used to handle critical enterprise messaging. An authenticated attacker can trigger a heap buffer overflow during queue manager startup by sending malformed cluster migration data, causing service outages or potentially executing arbitrary code on the server.
Technical details
The vulnerability is a heap-based buffer overflow (CWE-122) in improper validation of cluster migration data during queue manager startup. An authenticated attacker with network access can exploit this via the MQ cluster protocol to cause denial of service or arbitrary code execution. A fix is available in CSU 8.1.0.41.
Affected products
- IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40
Timeline
- 2026-09-18: disclosed