ZeroHour

CVE-2026-12150

moderate

Buffer Overflow in IBM MQ TLS Certificate Parsing Enables DoS and Memory Access

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

IBM MQ contains a buffer overflow (CWE-121) in its TLS certificate processing path caused by improper validation of deeply nested certificate data. A remote attacker who already holds a trusted TLS client certificate can present a maliciously crafted certificate during the mutual-TLS handshake to crash the queue manager (denial of service) and potentially read or alter memory contents, reflected in the CVSS 3.1 base score of 7.0 (high) with C:L/I:L/A:H and high attack complexity. All supported IBM MQ streams are affected, spanning 9.1 through 9.4 LTS and CD releases plus 10.0.0.0. The trusted-certificate prerequisite narrows the attacker pool to holders of valid client credentials, compromised clients, or rogue insiders, but messaging backbones that fail can take dependent applications down with them. No public proof of concept exists and the flaw is not in CISA's KEV catalog, so no exploitation is currently known.

What to do: Apply the fixed refresh or fix pack IBM specifies in its advisory for your stream (9.1 LTS, 9.2 LTS, 9.3 LTS/CD, 9.4 LTS/CD, and 10.0), prioritizing queue managers that accept client certificates from broad or externally managed CAs. Tighten mutual-TLS trust stores so only tightly controlled CAs can issue usable client certificates, and revoke unused client certificates to shrink the attacker pool. Review channel and error logs for unexplained queue-manager crashes or handshake failures from otherwise authenticated clients, which would be the strongest indicator of attempted exploitation.

Affected
IBM MQ9.1.0.0 - 9.1.0.37 LTS
IBM MQ9.2.0.0 - 9.2.0.43 LTS
IBM MQ9.3.0.0 - 9.3.0.41 LTS
IBM MQ9.3.0.0 - 9.3.5.1 CD
IBM MQ9.4.0.0 - 9.4.0.25 LTS
IBM MQ9.4.0.0 - 9.4.5.1 CD
IBM MQ10.0.0.0
Estimated exposure
moderate≈10,000 internet-exposed IBM MQ listeners, plus a substantially larger internal-only enterprise install base — Public internet scan services (Shodan/Censys) have historically shown on the order of ten thousand IBM MQ queue-manager and admin listeners reachable on the open internet, while the product's core deployment base is internal enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during TLS certificate processing.

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.