CVE-2024-40680: IBM MQ denial of service
IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.
Other sources
IBM MQ could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40680?
The severity of CVE-2024-40680 is classified as a denial of service vulnerability due to improper memory allocation.
How do I fix CVE-2024-40680?
To fix CVE-2024-40680, it is recommended to update IBM MQ to the latest version that includes the security patch addressing this vulnerability.
Which versions of IBM MQ are affected by CVE-2024-40680?
Affected versions of IBM MQ include 9.3 and 9.4 LTS/CD, as well as various specific releases of IBM MQ Operator and supplied MQ Advanced container images.
What type of attack does CVE-2024-40680 facilitate?
CVE-2024-40680 facilitates a local denial of service attack, potentially causing service disruption.
Can CVE-2024-40680 be exploited remotely?
No, CVE-2024-40680 can only be exploited by a local user.