{"id":"CVE-2026-6730","published":"2026-09-23T21:17:02.053","lastModified":"2026-09-28T20:47:20.347","description":"IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-120"],"vendors":["ibm","linux"],"products":["concert","linux kernel"],"references":[{"url":"https://www.ibm.com/support/pages/node/7288830","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a buffer overflow in IBM Concert 1.0.0 through 3.0.0 due to improper bounds checking, allowing a local user to execute arbitrary code. This vulnerability is critical as it can lead to full system compromise.","exploitability":"Exploitation is relatively straightforward for a local user with access to the affected system. No specific preconditions other than local access are required.","blast_radius":"If exploited, the impact is high, as it allows the execution of arbitrary code, potentially leading to complete system compromise and loss of data or control.","remediation":"Upgrade to IBM Concert 3.1.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","local-privilege-escalation","buffer-overflow"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:51:42.480Z"}}