CVE-2025-3631
published 2025-07-11CVE-2025-3631: An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
22.7th percentile
An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | mq | 9.3.2.0 CD – 9.3.5.1 CD | — |
| ibm | mq | 9.4.0.0 – 9.4.2.1 CD | — |
| ibm | mq | 9.4.0.0 LTS – 9.4.0.11 LTS | — |
| ibm | mq_appliance | 9.3.2 – 9.3.5.2 | — |
| ibm | mq_appliance | 9.3.2.0 CD – 9.3.5.2 CD | — |
| ibm | mq_appliance | >= 9.4.0.0 < 9.4.0.12 | 9.4.0.12 |
| ibm | mq_appliance | >= 9.4.0.0 < 9.4.3 | 9.4.3 |
| ibm | mq_appliance | 9.4.0.0 LTS – 9.4.0.11 LTS | — |
| ibm | mq_appliance | >= 9.4.1.0 < 9.4.3.0 | 9.4.3.0 |
| ibm | mq_appliance | 9.4.1.0 CD – 9.4.2.1 CD | — |
| msrc | cm1_libvirt_6.1.0-5_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mprx-jp8f-rw8w: An IBM MQ 9
ghsa_unreviewed·2025-07-11
CVE-2025-3631 [MEDIUM] CWE-416 GHSA-mprx-jp8f-rw8w: An IBM MQ 9
An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
Microsoft
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the break
vendor_msrc·2022-03-08·CVSS 6.3
CVE-2021-3631 [MEDIUM] CWE-732 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the break
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-11
Published