CVE-2026-82344: IBM Guardium Data Protection Buffer Overflow
IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.
Other sources
IBM Security Guardium is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protection Windows S-TAPto a version that resolves this vulnerability.Patch Guardium_12.x.p101_r120203346_S-TAP_Windows
Event History
Frequently Asked Questions
Which deployments should be prioritized for assessment?
IBM Guardium Data Protection versions 12.0 and 12.1 are identified as affected. The exposed component is the S-TAP TrafficTap TDS login reassembly functionality.
Does an attacker need credentials or user interaction to exploit this issue?
No. The vulnerability is described as remotely exploitable by an unauthenticated attacker, with no user interaction required, by sending crafted TDS login fragments.