IBM MQ Operator SIGSEGV Vulnerability in AMQRMPPA Channel Process

Vulnerability

A use-after-free vulnerability has been identified in IBM MQ Operator versions 2.0.0 through 2.0.29, as well as several 3.x versions. When a client connects to an MQ Queue Manager, this vulnerability can cause a segmentation fault (SIGSEGV) in the AMQRMPPA channel process, leading to its termination. The root cause involves improper handling of memory, allowing for a connection to disrupt the channel process.

Impact

Exploitation of this vulnerability causes a segmentation fault in the AMQRMPPA channel process, terminating it.

Remediation

Users can upgrade to IBM MQ Operator v3.5.2 or v3.2.11, both of which include the necessary fix. Additionally, the IBM MQ Container version 9.4.2.1-r1 is also available as a patched option.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.