DEBIAN-CVE-2026-40342

Source
https://security-tracker.debian.org/tracker/CVE-2026-40342
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40342.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-40342
Upstream
Published
2026-04-17T20:16:35Z
Modified
2026-09-14T17:03:32Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during loading, before Firebird validates the module, achieving code execution as the server's OS account. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

References

Affected packages

Debian:12 / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.11.33637.ds4-2
3.0.11.33637.ds4-2+deb12u1
3.0.11.33637.ds4-2+m68k
3.0.11.33637.ds4-2+m68k.1
3.0.11.33703.ds4-1
3.0.11.33703.ds4-2
3.0.11.33703.ds4-3
3.0.11.33703.ds4-3+exp.0
3.0.11.33703.ds4-3+exp.1
3.0.11.33703.ds4-3+m68k
3.0.11.33703.ds4-4
3.0.11.33703.ds4-4+exp.0
3.0.11.33703.ds4-4+m68k
3.0.12.ds5-1
3.0.12.ds5-2
3.0.12.ds7-1
3.0.12.ds7-2
3.0.12.ds7-3
3.0.12.ds7-3+exp.0
3.0.12.ds7-5
3.0.12.ds7-5+exp1
3.0.12.ds7-6
3.0.12.ds7-7
3.0.12.ds7-7+exp1
3.0.12.ds7-8
3.0.12.ds7-9
3.0.12.ds7-10
3.0.12.ds7-11
3.0.12.ds7-12
3.0.12.ds7-13
3.0.12.ds7-13+m68k
3.0.12.ds7-13+m68k.1
3.0.13.ds7-1
3.0.13.ds7-2
3.0.14.ds7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40342.json"

Debian:13 / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.12.ds7-13
3.0.12.ds7-13+deb13u1
3.0.12.ds7-13+m68k
3.0.12.ds7-13+m68k.1
3.0.13.ds7-1
3.0.13.ds7-2
3.0.14.ds7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40342.json"

Debian:14 / firebird3.0

Package

Name
firebird3.0
Purl
pkg:deb/debian/firebird3.0?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.14.ds7-1

Affected versions

3.*
3.0.12.ds7-13
3.0.12.ds7-13+m68k
3.0.12.ds7-13+m68k.1
3.0.13.ds7-1
3.0.13.ds7-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40342.json"

Debian:13 / firebird4.0

Package

Name
firebird4.0
Purl
pkg:deb/debian/firebird4.0?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.0.5.3140.ds6-17
4.0.5.3140.ds6-17+deb13u1
4.0.5.3140.ds6-17+m68k
4.0.6.3221.ds6-1
4.0.6.3221.ds6-2
4.0.7.3271.ds6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40342.json"

Debian:14 / firebird4.0

Package

Name
firebird4.0
Purl
pkg:deb/debian/firebird4.0?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.0.7.3271.ds6-1

Affected versions

4.*
4.0.5.3140.ds6-17
4.0.5.3140.ds6-17+m68k
4.0.6.3221.ds6-1
4.0.6.3221.ds6-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40342.json"