Executive brief
IBM MQ is a messaging middleware used by enterprises to route business-critical transactions and data between applications. The C client component fails to validate responses from queue managers when processing AMS security policy data, allowing a remote attacker to trigger a heap buffer overflow. This can cause the client application to crash (denial of service) or execute arbitrary code on the system running the client.
Technical details
A heap-based buffer overflow exists in the IBM MQ C client's handling of queue manager responses during AMS (Application Messaging Services) policy data requests due to improper input validation. The vulnerability is remotely exploitable over the network with no authentication or user interaction required, affecting versions 8.1.0 through 8.1.0.40. A patched version 8.1.0.41 is available.
Affected products
- IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: CSU 8.1.0.41 released