Executive brief
IBM MQ is a message queueing system used by enterprises to route and deliver messages between applications. An authenticated attacker could exploit an integer overflow in the MQINQ request processor to crash the queue manager (denial of service) or execute arbitrary code with queue manager privileges, potentially compromising the entire messaging infrastructure.
Technical details
An integer overflow in IBM MQ's MQINQ request validation allows an authenticated network attacker to trigger memory corruption. The vulnerability requires existing authentication credentials and network access to the queue manager, but no user interaction. Successful exploitation grants arbitrary code execution in the context of the queue manager process.
Affected products
- IBM MQ 9.1.0.0 to 9.1.0.37 LTS
- IBM MQ 9.2.0.0 to 9.2.0.43 LTS
- IBM MQ 9.3.0.0 to 9.3.0.41 LTS
- IBM MQ 9.3.0.0 to 9.3.5.1 CD
- IBM MQ 9.4.0.0 to 9.4.0.25 LTS
- IBM MQ 9.4.0.0 to 9.4.5.1 CD
- IBM MQ 10.0.0.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixes available: MQ 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26 LTS; 10.0.0.5 for CD and latest