


Perceptive Security
SOC/SIEM Consultancy

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the le…
Published:
16 april 2026 om 22:00:00
Alert date:
17 april 2026 om 21:03:48
Source:
nvd.nist.gov
Database & Storage
A denial of service vulnerability exists in Firebird open-source database management system versions prior to 5.0.4, 4.0.7 and 3.0.14. The sdl_desc() function fails to validate the length of decoded SDL descriptors from slice packets. When a zero-length descriptor is processed, it causes a division by zero error during slice item calculation. Unauthenticated attackers can exploit this flaw by sending specially crafted slice packets to crash the database server. The vulnerability has been patched in the latest versions across all affected branches.
Technical details
Mitigation steps:
Affected products:
Firebird
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35215
https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14
https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7
https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4
https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-g99w-prq5-29c6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
