CVE-2026-10858: IBM MQ for HPE NonStop is vulnerable to a denial of service attack
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
Other sources
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ for HPE NonStop 8.1to a version that resolves this vulnerability.Fixed in 8.1.0.41Patch IT49924
Event History
Frequently Asked Questions
Which deployments are affected?
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 are affected.
What access does an attacker need to exploit this issue?
An attacker must be authenticated to IBM MQ. No user interaction is required.
What message handling triggers the vulnerability?
The issue occurs when IBM MQ processes multi-segment messages, leading to a heap buffer underflow.
What is the potential impact of successful exploitation?
A successful attacker could cause a denial of service and may potentially execute arbitrary code.