Impact
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 contains a heap buffer underflow flaw that occurs when processing multi-segment messages. An attacker who has authenticated credentials can trigger the underflow, leading to program instability that may cause a denial of service or, in some circumstances, execution of arbitrary code. The vulnerability is a classic buffer underflow (CWE-122) that can be leveraged to compromise the reliability and integrity of the messaging system.
Affected Systems
The affected product is IBM MQ for HPE NonStop, version 8.1.0.0 up to 8.1.0.40 inclusive. Systems that have not applied the July 2026 CSU 8.1.0.41 update remain vulnerable. The patch addresses the heap buffer underflow in the MQ message handling component.
Risk and Exploitability
The vulnerability has a CVSS score of 9.9, indicating a high likelihood of severe impact under the appropriate conditions. The EPSS score is < 1%, indicating a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access, an attacker must first compromise valid user credentials on the NonStop platform; once authenticated, the attacker can invoke the bug through the standard MQ client libraries or internal components, potentially disrupting critical messaging services or executing code with the MQ process’s privileges.
OpenCVE Enrichment