Executive brief
IBM Db2 is a widely-used enterprise database management system. A memory leak vulnerability in Db2 12.1.5 allows local attackers to exhaust server memory and cause service outages, disrupting critical business applications that depend on the database.
Technical details
This vulnerability is a resource exhaustion flaw (CWE-770) in IBM Db2 12.1.5 for Linux, UNIX, and Windows (including DB2 Connect Server). A local attacker with low privileges can trigger a memory leak that gradually consumes available system memory without bounds, eventually causing denial of service. The attack requires local access to the system and no user interaction. IBM has released security updates through Fix Central; customers should apply Security Update #88454 or later for Db2 v12.1.5.
Affected products
- IBM Db2 12.1.5
Timeline
- 2026-08-07: disclosed
- 2026-08-12: advisory