Executive brief
IBM Db2 is a widely-used enterprise database management system that processes data imports in IXF (Integration Exchange Format) files. A buffer overflow vulnerability in the import parser allows local attackers to cause a denial of service or potentially execute arbitrary code on systems running affected versions. This could lead to unauthorized access to sensitive business data or disruption of database operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in the IXF IMPORT parser of IBM Db2. The vulnerability requires local access to the affected system (no network vector) and no user authentication is required, meaning any local user can trigger the flaw by providing a specially crafted IXF import file. Successful exploitation can lead to high-impact consequences including disclosure of confidential data, data integrity compromise, and complete availability loss. IBM has released security updates for Db2 11.5.9 and 12.1.4/12.1.5; patches are available via IBM Fix Central and referenced security bulletins.
Affected products
- IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
Timeline
- 2026-08-07: disclosed