CVE-2025-54989 Details
Description
Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS. This issue has been patched in versions 3.0.13, 4.0.6, and 5.0.3.
A denial-of-service vulnerability has been identified in Firebird relational database management system, prior to versions 3.0.13, 4.0.6, and 5.0.3. The issue arises from a NULL pointer dereference during the parsing of XDR messages from clients, leading to a crash or unresponsiveness of the database server.
Users can upgrade to Firebird versions 3.0.13, 4.0.6, or 5.0.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| firebirdsql firebird | < 3.0.13 >= 4.0.0, < 4.0.6 >= 5.0.0, < 5.0.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 22, 2025 | Reanalysis | [email protected] |
| Aug 21, 2025 | Initial Analysis | [email protected] |
| Aug 15, 2025 | New CVE Received | [email protected] |