CVE-2025-2900: IBM Semeru Runtime denial of service
IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2900?
CVE-2025-2900 has a high severity level due to its potential to cause a denial of service.
How do I fix CVE-2025-2900?
To fix CVE-2025-2900, upgrade to versions of IBM Semeru Runtime that are not affected, specifically those released after 8.0.442.0, 11.0.26.0, 17.0.14.0, and 21.0.6.0.
What causes CVE-2025-2900?
CVE-2025-2900 is caused by a buffer overflow in the native AES/CBC encryption implementation in specific versions of IBM Semeru Runtime.
Which versions of IBM Semeru Runtime are affected by CVE-2025-2900?
Affected versions include 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 21.0.6.0.
What are the risks of not addressing CVE-2025-2900?
Failure to address CVE-2025-2900 can lead to unexpected application crashes and service interruptions.