CVE Vulnerabilities

CVE-2025-36118

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Published: Nov 17, 2025 | Modified: Dec 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

Weakness

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Affected Software

NameVendorStart VersionEnd Version
Storage_virtualizeIbm8.4.0.0 (including)8.4.0.0 (including)
Storage_virtualizeIbm8.5.0.0 (including)8.5.0.0 (including)
Storage_virtualizeIbm8.7.0.0 (including)8.7.0.0 (including)
Storage_virtualizeIbm9.1.0.0 (including)9.1.0.0 (including)

References