Integer overflow in Firebird - CVE-2026-28214

 

Integer overflow in Firebird - CVE-2026-28214

Published: April 20, 2026


Vulnerability identifier: #VU126556
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28214
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an integer overflow in ClumpletReader::getClumpletSize() when parsing a batch parameter block clumplet during batch creation. A remote user can send a specially crafted batch parameter block to cause a denial of service.

Exploitation requires valid authentication and INSERT privilege on a table.


Affected software

Firebird
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
firebird
firebird-debugsource
libib_util
firebird-examples
libfbclient2
libib_util-debuginfo
firebird-utils
firebird-server
libib_util-devel
libfbclient2-debuginfo
firebird-server-debuginfo
firebird-utils-debuginfo
libfbclient-devel
firebird-debuginfo

How to mitigate CVE-2026-28214

Install security update from vendor's website.

Firebird - addressed in versions 3.0.14, 4.0.7, 5.0.4
firebird - update to 3.0.14.33856-150200.3.9.1
firebird-debugsource - update to 3.0.14.33856-150200.3.9.1
libib_util - update to 3.0.14.33856-150200.3.9.1
firebird-examples - update to 3.0.14.33856-150200.3.9.1
libfbclient2 - update to 3.0.14.33856-150200.3.9.1
libib_util-debuginfo - update to 3.0.14.33856-150200.3.9.1
firebird-utils - update to 3.0.14.33856-150200.3.9.1
firebird-server - update to 3.0.14.33856-150200.3.9.1
libib_util-devel - update to 3.0.14.33856-150200.3.9.1
libfbclient2-debuginfo - update to 3.0.14.33856-150200.3.9.1
firebird-server-debuginfo - update to 3.0.14.33856-150200.3.9.1
firebird-utils-debuginfo - update to 3.0.14.33856-150200.3.9.1
libfbclient-devel - update to 3.0.14.33856-150200.3.9.1
firebird-debuginfo - update to 3.0.14.33856-150200.3.9.1

External References

Related Security Bulletins