CVE-2026-12150
moderateBuffer Overflow in IBM MQ TLS Certificate Parsing Enables DoS and Memory Access
IBM MQ contains a buffer overflow (CWE-121) in its TLS certificate processing path caused by improper validation of deeply nested certificate data. A remote attacker who already holds a trusted TLS client certificate can present a maliciously crafted certificate during the mutual-TLS handshake to crash the queue manager (denial of service) and potentially read or alter memory contents, reflected in the CVSS 3.1 base score of 7.0 (high) with C:L/I:L/A:H and high attack complexity. All supported IBM MQ streams are affected, spanning 9.1 through 9.4 LTS and CD releases plus 10.0.0.0. The trusted-certificate prerequisite narrows the attacker pool to holders of valid client credentials, compromised clients, or rogue insiders, but messaging backbones that fail can take dependent applications down with them. No public proof of concept exists and the flaw is not in CISA's KEV catalog, so no exploitation is currently known.
What to do: Apply the fixed refresh or fix pack IBM specifies in its advisory for your stream (9.1 LTS, 9.2 LTS, 9.3 LTS/CD, 9.4 LTS/CD, and 10.0), prioritizing queue managers that accept client certificates from broad or externally managed CAs. Tighten mutual-TLS trust stores so only tightly controlled CAs can issue usable client certificates, and revoke unused client certificates to shrink the attacker pool. Review channel and error logs for unexplained queue-manager crashes or handshake failures from otherwise authenticated clients, which would be the strongest indicator of attempted exploitation.
| IBM MQ | 9.1.0.0 - 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 - 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 - 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 - 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 - 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 - 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during TLS certificate processing.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.