Executive brief
IBM Db2 is a database management system used to store and manage large volumes of corporate data. A security flaw in a specific helper component could allow a user with limited access to the system to gain higher-level permissions and potentially take full control of the database instance. This could lead to unauthorized access to sensitive information or a complete disruption of database services.
Technical details
A stack-based buffer overflow (CWE-121) exists in the db2flacc setgid helper component of IBM Db2. The vulnerability can be triggered by a local attacker with access to an unprivileged shell on Linux or Unix platforms. By exploiting this overflow, an attacker can escalate their privileges, potentially leading to full compromise of the Db2 instance. The issue affects versions 11.5 (up to 11.5.9) and 12.1 (up to 12.1.4). IBM has released special builds for V11.5.9 and V12.1.4 to remediate the flaw; Windows installations are not affected.
Affected products
- IBM Db2 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-07-10: disclosed: Initial publication by IBM
- 2026-07-14: advisory: Updated to specify privilege escalation impact
- 2026-07-30: advisory: NVD publication date