Executive brief
IBM Db2, a widely used enterprise database management system, is vulnerable to a denial of service. An attacker with local access to the system can execute a specifically crafted database query that causes the service to crash or become unresponsive. This could lead to business disruptions and loss of database availability for legitimate users and applications.
Technical details
IBM Db2 (versions 11.5 and 12.1) is susceptible to uncontrolled resource consumption (CWE-400) during query execution. The vulnerability is triggered when a specially crafted query is processed in an environment with a small statement heap (STMTHEAP). An authenticated local attacker can exploit this to cause a denial of service condition. IBM has released special builds for versions 11.5.9 and 12.1.4 to address the issue. Temporary mitigations include increasing the STMTHEAP configuration parameter or reducing the query optimization level to 0.
Affected products
- IBM Db2 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-05-21: disclosed: Initial publication by IBM
- 2026-05-21: patched: Special builds released for 11.5.9 and 12.1.4
- 2026-05-27: advisory: NVD publication date