CVE Vulnerabilities

CVE-2024-40680

Memory Allocation with Excessive Size Value

Published: Sep 07, 2024 | Modified: Oct 31, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.

Weakness

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Affected Software

Name Vendor Start Version End Version
Mq_operator Ibm 2.0.26 (including) 2.0.26 (including)
Mq_operator Ibm 3.2.4 (including) 3.2.4 (including)

Potential Mitigations

References