Summary
CVE-2026-84058 is a buffer overrun vulnerability (CWE-119) in the TDS (Microsoft SQL Server) PRELOGIN packet decoder of IBM Guardium Data Protection 12.0, 12.1 and 12.2. A remote, unauthenticated attacker can send a crafted packet to cause denial of service or potentially execute arbitrary code on the Collector appliance. The CVSS v3.1 base score is 8.1 (High).
Technical details
- Root cause: buffer overrun (CWE-119, improper restriction of operations within the bounds of a memory buffer) in the TDS (Microsoft SQL Server) PRELOGIN packet decoder.
- Trigger conditions: a specially crafted PRELOGIN packet is sent to the affected component. No authentication or user interaction is required; attack complexity is rated high.
- Attack vector: network.
- Impact: denial of service, or potentially arbitrary code execution, on the Collector appliance.
Affected software
- IBM Guardium Data Protection 12.0
- IBM Guardium Data Protection 12.1
- IBM Guardium Data Protection 12.2
Severity
CVSS v3.1 base score 8.1 (High): CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the patch published by IBM through Fix Central (a Sniffer component update) as described in the IBM security bulletin. Specific patch identifiers are listed in that bulletin.
- Workarounds: IBM lists none. Patching is the only remediation.

