VYPR
Unrated severityNVD Advisory· Published Apr 27, 2023· Updated Feb 13, 2025

IBM DB2 for Linux, UNIX and Windows denial of service

CVE-2023-29255

Description

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Db2 for Linux, UNIX and Windows traps when compiling a variation of an anonymous block, allowing remote unauthenticated denial of service.

Vulnerability

IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) versions 10.5, 11.1, and 11.5 at any fix pack level are vulnerable to a denial of service when compiling a specific variation of an anonymous block [1]. The vulnerability causes the database to trap (crash), leading to service unavailability [1].

Exploitation

No authentication is required [1]. An attacker with network access can send a crafted SQL anonymous block to a vulnerable Db2 server, triggering the trap during compilation. No special privileges are needed, and the attack does not require user interaction [1].

Impact

Successful exploitation results in a denial of service, as the Db2 process traps and becomes unavailable [1]. The impact is limited to availability (CIA: none on confidentiality or integrity), with high availability impact per CVSS score of 7.5 [1].

Mitigation

IBM has released special builds containing interim fixes for affected releases: V10.5 FP11, V11.1.4 FP7, V11.5.7, and V11.5.8. These can be downloaded from IBM Fix Central for the appropriate platform [1]. Customers should apply the special build corresponding to their release. No workaround is available, but the interim fix remediates the vulnerability [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.