CVE-2026-6100
IBM QRadar SIEM: Mehrere Schwachstellen
Weakness-Klassen (CWE)
CWE-416Variant
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
cwe.mitre.org →CWE-787Base
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →
Beschreibung
Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen. IBM QRadar Security Information and Event Management (SIEM) bietet Unterstützung bei der Erkennung und Priorisierung von Sicherheitsbedrohungen im Unternehmen.
Quelle: BSI
Betroffene Betriebssysteme
linux
amazon / amazon_linux
linux
suse / basesystem_module15
linux
debian / debian_linux11.0
linux
debian / debian_linux12.0
linux
debian / debian_linux13.0
linux
suse / development_tools_module15
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux6.0
linux
redhat / enterprise_linux7.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux_aus8.4
linux
redhat / enterprise_linux_aus8.6
linux
redhat / enterprise_linux_eus10.0
linux
redhat / enterprise_linux_eus8.4
linux
redhat / enterprise_linux_eus9.4
linux
redhat / enterprise_linux_eus9.6
linux
redhat / enterprise_linux_server_aus8.2
linux
redhat / enterprise_linux_server_aus8.4
linux
redhat / enterprise_linux_tus8.6
linux
redhat / enterprise_linux_tus8.8
linux
redhat / enterprise_linux_update_services_for_sap_solutions8.6
linux
redhat / enterprise_linux_update_services_for_sap_solutions8.8
linux
redhat / enterprise_linux_update_services_for_sap_solutions9.0
Quellen & Referenzen
- https://kb.isc.org/docs/cve-2026-1519vendor-advisory
- https://downloads.isc.org/isc/bind9/9.18.47patch
- https://downloads.isc.org/isc/bind9/9.20.21patch
- https://downloads.isc.org/isc/bind9/9.21.20patch
- https://www.openssh.org/releasenotes.html#10.3p1
- https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
- https://www.openwall.com/lists/oss-security/2026/04/02/3
- https://github.com/vim/vim/security/advisories/GHSA-m3xh-9434-g336x_refsource_CONFIRM
- https://github.com/vim/vim/commit/79348dbbc09332130f4c860x_refsource_MISC
- https://github.com/vim/vim/releases/tag/v9.2.0073x_refsource_MISC
- https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9x_refsource_CONFIRM
- https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615x_refsource_MISC
- https://github.com/vim/vim/releases/tag/v9.2.0276x_refsource_MISC
- https://www.ibm.com/support/pages/node/7273957vendor-advisorypatch
- https://git.kernel.org/stable/c/f9fcb4441f6c02bb20c2eb340101e27dfe23607ceuvd
- https://git.kernel.org/stable/c/c9452c0797c95cf2378170df96cf4f4b3bca7effeuvd
- https://git.kernel.org/stable/c/8afb437ea1f70cacb4bbdf11771fb5c4d720b965euvd
- https://git.kernel.org/stable/c/dad0c3c0a8e5d1d6eb0fc455694ce3e25e6c57d0euvd
- https://git.kernel.org/stable/c/0f0e2a54a31a7f9ad2915db99156114872317388euvd
- https://git.kernel.org/stable/c/ae8498337dfdfda71bdd0b807c9a23a126011d76euvd
Verknüpfte CVEs
- CVE-2026-5121highCVSSv3 7.5
- CVE-2026-4786highCVSSv3 7.1
- CVE-2026-4519lowCVSSv3 3.3
- CVE-2026-4424highCVSSv3 7.5
- CVE-2026-35535highCVSSv3 7.8
- CVE-2026-35414highCVSSv3 8.1
- CVE-2026-35388lowCVSSv3 2.5
- CVE-2026-35387mediumCVSSv3 6.5
- CVE-2026-35386highCVSSv3 8.1
- CVE-2026-35385highCVSSv3 8.1
- CVE-2026-34982highCVSSv3 8.2
- CVE-2026-33412highCVSSv3 7.3
- CVE-2026-31431Aktiv ausgenutzthighCVSSv3 7.8
- CVE-2026-31402criticalCVSSv3 9.8
- CVE-2026-28421mediumCVSSv3 5.3
- CVE-2026-28417mediumCVSSv3 4.4
- CVE-2026-27135highCVSSv3 7.5
- CVE-2026-23401mediumCVSSv3 5.5
- CVE-2026-23191highCVSSv3 7.8
- CVE-2026-1519highCVSSv3 7.5
- CVE-2025-68741—CVSSv3 0.0
- CVE-2025-68724—CVSSv3 0.0
- CVE-2025-40252—CVSSv3 0.0
- CVE-2024-56462highCVSSv3 7.2