Executive brief
IBM Db2 Mirror for i is a database mirroring solution used to ensure high availability and disaster recovery for IBM database systems. A remote attacker can exploit an uncontrolled recursion vulnerability to crash the service, causing a denial of service and disrupting business-critical database operations without requiring authentication.
Technical details
This vulnerability is caused by uncontrolled recursion in IBM Db2 Mirror for i, which allows a remote, unauthenticated attacker to trigger excessive recursive function calls. The vulnerable component processes incoming requests without properly limiting recursion depth. An attacker can craft a specially formed network request to exploit this flaw, causing the service process to exhaust stack memory and crash, resulting in denial of service. The vulnerability affects versions 7.4, 7.5, and 7.6, and patches are available from IBM.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed