Improper Pointer Validation in IBM Guardium Data Protection
CVE-2026-84290

5.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 October 2026

What is CVE-2026-84290?

IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are susceptible to an improper validation of user-supplied pointers within the WfpMonitor kernel driver. This vulnerability exists in specific METHOD_NEITHER IOCTL handlers that inadequately handle user-controlled pointers, which may lead to a local attacker with privileged access potentially causing a system crash or performing unauthorized reads from kernel memory. Ensuring robust validation measures and timely patch application is essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

Guardium Data Protection 12.0

Guardium Data Protection 12.1

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.