Junglewise Threat Intelligence

CVE-2026-6052: IBM Db2 denial of service via memory exhaustion in MDC tables

CVE-2026-6052 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: IBM Db2. Vendors: IBM.

Executive brief

IBM Db2 is a widely used database management system for enterprise data storage and analysis. A vulnerability has been identified where certain database queries involving Multi-Clustering-Dimensional (MDC) tables can cause the system to run out of memory. This can lead to a denial-of-service condition, potentially crashing the database and disrupting business operations and application availability.

Technical details

IBM Db2 versions 11.5 (up to 11.5.9) and 12.1 (up to 12.1.4) contain a resource exhaustion vulnerability. The flaw is triggered when the database engine executes specific queries against Multi-Clustering-Dimensional (MDC) tables, leading to excessive memory consumption. An authenticated attacker with network access and the ability to execute queries can exploit this to cause a denial-of-service (DoS) by exhausting available system memory. IBM has released special builds (interim fixes) for versions 11.5.9 and 12.1.4 to address the issue. As a temporary mitigation, users are advised to avoid the use of MDC tables where possible.

Affected products

  • IBM Db2 11.5.0 - 11.5.9, 12.1.0 - 12.1.4

Timeline

  • 2026-05-21: disclosed: Initial publication by IBM
  • 2026-05-21: patched: Special builds released for 11.5.9 and 12.1.4
  • 2026-05-27: advisory: NVD publication date

References

Related threats