{"id":"CVE-2026-10575","published":"2026-09-18T16:17:04.150","lastModified":"2026-09-23T18:32:15.760","description":"IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-122"],"vendors":["ibm"],"products":["mq"],"references":[{"url":"https://www.ibm.com/support/pages/node/7287778","tags":["Patch","Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in IBM MQ allows an authenticated attacker to cause a denial of service or potentially escalate privileges through a heap buffer overflow during MQPUT operations with malformed distribution headers.","exploitability":"Exploitation requires an authenticated attacker and malformed distribution headers, making it moderately difficult to exploit.","blast_radius":"If exploited, the impact could be significant, leading to service disruption or privilege escalation.","remediation":"Upgrade to IBM MQ 9.2.5.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["dos","privilege-escalation","heap-buffer-overflow"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:23:48.674Z"}}