Integer overflow in Firebird - CVE-2026-28214
Published: April 20, 2026
Firebird
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an integer overflow in ClumpletReader::getClumpletSize() when parsing a batch parameter block clumplet during batch creation. A remote user can send a specially crafted batch parameter block to cause a denial of service.
Exploitation requires valid authentication and INSERT privilege on a table.