{"id":"CVE-2026-6928","published":"2026-09-23T21:17:02.430","lastModified":"2026-09-29T14:08:24.273","description":"IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-416"],"vendors":["ibm","linux"],"products":["concert","linux kernel"],"references":[{"url":"https://www.ibm.com/support/pages/node/7288830","tags":["Patch","Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in IBM Concert allows an attacker to corrupt memory, causing application crashes or executing arbitrary code by referencing or accessing memory that has been freed.","exploitability":"Exploitation is relatively straightforward for an attacker who can influence program execution or input.","blast_radius":"If exploited, the impact could be severe, potentially leading to full system compromise or data loss.","remediation":"Upgrade to IBM Concert 3.1.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","memory-corruption","critical","application-crash"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:51:46.893Z"}}