CVE-2026-28212: Firebird has potential server crash via null pointer dereference when processing op_slice packet
Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an opslice network packet, the server passes an unprepared structure containing a null pointer to the SDLinfo() function, resulting in a null pointer dereference and server crash. An unauthenticated attacker can trigger this by sending a crafted packet to the server port. This issue has been fixed in versions 6.0.0, 5.0.4, 4.0.7 and 3.0.14.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28212?
CVE-2026-28212 has a severity associated with potential server crashes due to null pointer dereferences.
How do I fix CVE-2026-28212?
To fix CVE-2026-28212, upgrade Firebird to version 6.0.0 or later, 5.0.4 or later, 4.0.7 or later, or 3.0.14 or later.
Which versions are affected by CVE-2026-28212?
CVE-2026-28212 affects Firebird versions prior to 6.0.0, 5.0.4, 4.0.7, and 3.0.14.
What kind of issues can arise from CVE-2026-28212?
CVE-2026-28212 can lead to a server crash when processing certain network packets.
Is CVE-2026-28212 a critical vulnerability?
CVE-2026-28212 is serious because it can cause server instability, affecting availability.