CVE-2025-3631Use After Free in IBM MQ Appliance

Severity
7.5HIGHNVD
CNA6.5
EPSS
0.1%
top 81.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 11

Description

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDibm/mq_appliance9.4.0.09.4.0.12+3
CVEListV5ibm/mq9.3.2.0 CD9.3.5.1 CD+2
CVEListV5ibm/mq_appliance9.3.2.0 CD9.3.5.2 CD+2

🔴Vulnerability Details

2
GHSA
GHSA-mprx-jp8f-rw8w: An IBM MQ 92025-07-11
CVEList
IBM MQ denial of service2025-07-11

📋Vendor Advisories

1
Microsoft
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the break2022-03-08
CVE-2025-3631 — Use After Free in IBM MQ Appliance | cvebase