CVE Vulnerabilities

CVE-2025-36118

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Published: Nov 17, 2025 | Modified: Dec 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

Weakness

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Affected Software

Name Vendor Start Version End Version
Storage_virtualize Ibm 8.4.0.0 (including) 8.4.0.0 (including)
Storage_virtualize Ibm 8.5.0.0 (including) 8.5.0.0 (including)
Storage_virtualize Ibm 8.7.0.0 (including) 8.7.0.0 (including)
Storage_virtualize Ibm 9.1.0.0 (including) 9.1.0.0 (including)

References