CVE-2025-54989: Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability
Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54989?
CVE-2025-54989 is classified as a denial-of-service vulnerability.
How do I fix CVE-2025-54989?
To remediate CVE-2025-54989, upgrade Firebird to version 3.0.13, 4.0.6, or 5.0.3 or later.
What impacts does CVE-2025-54989 have on my Firebird database?
CVE-2025-54989 can lead to a denial-of-service condition through NULL pointer dereference during XDR message parsing.
Which versions of Firebird are affected by CVE-2025-54989?
CVE-2025-54989 affects Firebird versions prior to 3.0.13, 4.0.6, and 5.0.3.
Is CVE-2025-54989 critical for my application?
The impact of CVE-2025-54989 depends on your application usage, but it poses a significant risk of disruption due to its denial-of-service nature.