IBM DB2 for Linux, UNIX and Windows denial of service
Description
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Db2 for Linux, UNIX and Windows traps when compiling a variation of an anonymous block, allowing remote unauthenticated denial of service.
Vulnerability
IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 10.5, 11.1, and 11.5 at any fix pack level are vulnerable to a denial of service when compiling a specific variation of an anonymous block [1]. The vulnerability causes the database to trap (crash), leading to service unavailability [1].
Exploitation
No authentication is required [1]. An attacker with network access can send a crafted SQL anonymous block to a vulnerable Db2 server, triggering the trap during compilation. No special privileges are needed, and the attack does not require user interaction [1].
Impact
Successful exploitation results in a denial of service, as the Db2 process traps and becomes unavailable [1]. The impact is limited to availability (CIA: none on confidentiality or integrity), with high availability impact per CVSS score of 7.5 [1].
Mitigation
IBM has released special builds containing interim fixes for affected releases: V10.5 FP11, V11.1.4 FP7, V11.5.7, and V11.5.8. These can be downloaded from IBM Fix Central for the appropriate platform [1]. Customers should apply the special build corresponding to their release. No workaround is available, but the interim fix remediates the vulnerability [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 10.5, 11.1, 11.5
- Range: 10.5, 11.1, 11.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/pages/node/6985687mitrevendor-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/251991mitrevdb-entry
- security.netapp.com/advisory/ntap-20230511-0010/mitre
News mentions
0No linked articles in our index yet.