PT-2026-108161 · Ibm · Guardium Data Protection
CVE-2026-84290
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Guardium Data Protection versions 12.0 through 12.2
Description
The WfpMonitor kernel driver contains an improper validation of user-supplied pointers. Specifically, certain METHOD NEITHER IOCTL handlers dereference user-controlled pointers without sufficient probing and exception handling. This may allow a privileged local attacker to trigger a system crash or perform limited kernel-memory reads.
Recommendations
Update IBM Guardium Data Protection versions 12.0 through 12.2 to a version that contains the fix for this issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guardium Data Protection