Vulnerability CVE-2026-34232: Information

Description

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker can exploit this by sending a crafted op_response packet to the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: April 17, 2026
Modified: April 27, 2026
Error type identifier: CWE-228

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firebirdsisyphus5.0.4-alt15.0.4-alt1ALT-PU-2026-7100-2417095Fixed
firebirdsisyphus_loongarch645.0.4-alt15.0.4-alt1ALT-PU-2026-7495-1-Fixed
firebirdp115.0.4-alt15.0.4-alt1ALT-PU-2026-7136-2417164Fixed

References to Advisories, Solutions, and Tools

    1. cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
      Start including
      3.0.0
      End excluding
      3.0.14

      cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
      Start including
      4.0.0
      End excluding
      4.0.7

      cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
      Start including
      5.0.0
      End excluding
      5.0.4