SB2025092626 - Multiple vulnerabilities in IBM MQ Operator



SB2025092626 - Multiple vulnerabilities in IBM MQ Operator

Published: September 26, 2025

Security Bulletin ID SB2025092626
Severity
Low
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Protection Mechanism Failure (CVE-ID: CVE-2025-22874)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in crypto/x509 when using ExtKeyUsageAny. When calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny it disables policy validation.

This only affected certificate chains which contain policy graphs, which are rather uncommon.


2) Link following (CVE-ID: CVE-2025-8941)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an insecure link following issue in the pam_namespace module. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

The vulnerability exists due to incomplete fix for #VU111389 (CVE-2025-6020).


3) Improper access control (CVE-ID: CVE-2025-6020)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper access restrictions within the pam_namespace module when handling user-controlled paths. A local user can use specially crafted symlinks and race conditions to execute arbitrary code as root. 


Remediation

Install update from vendor's website.