Path traversal in Firebird - CVE-2026-40342
Published: April 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to path traversal in the external engine plugin loader when processing a CREATE FUNCTION statement with a crafted ENGINE name. A remote user can send a specially crafted SQL statement to execute arbitrary code.
The loaded library's initialization code runs immediately during loading, before Firebird verifies that the module is a valid plugin.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
firebird
firebird-debugsource
libib_util
firebird-examples
libfbclient2
libib_util-debuginfo
firebird-utils
firebird-server
libib_util-devel
libfbclient2-debuginfo
firebird-server-debuginfo
firebird-utils-debuginfo
libfbclient-devel
firebird-debuginfo
How to mitigate CVE-2026-40342
firebird - update to 3.0.14.33856-150200.3.9.1
firebird-debugsource - update to 3.0.14.33856-150200.3.9.1
libib_util - update to 3.0.14.33856-150200.3.9.1
firebird-examples - update to 3.0.14.33856-150200.3.9.1
libfbclient2 - update to 3.0.14.33856-150200.3.9.1
libib_util-debuginfo - update to 3.0.14.33856-150200.3.9.1
firebird-utils - update to 3.0.14.33856-150200.3.9.1
firebird-server - update to 3.0.14.33856-150200.3.9.1
libib_util-devel - update to 3.0.14.33856-150200.3.9.1
libfbclient2-debuginfo - update to 3.0.14.33856-150200.3.9.1
firebird-server-debuginfo - update to 3.0.14.33856-150200.3.9.1
firebird-utils-debuginfo - update to 3.0.14.33856-150200.3.9.1
libfbclient-devel - update to 3.0.14.33856-150200.3.9.1
firebird-debuginfo - update to 3.0.14.33856-150200.3.9.1