Executive brief
IBM Db2 is a widely used database management system for enterprise data storage and analysis. A vulnerability has been identified where certain database queries involving Multi-Clustering-Dimensional (MDC) tables can cause the system to run out of memory. This can lead to a denial-of-service condition, potentially crashing the database and disrupting business operations and application availability.
Technical details
IBM Db2 versions 11.5 (up to 11.5.9) and 12.1 (up to 12.1.4) contain a resource exhaustion vulnerability. The flaw is triggered when the database engine executes specific queries against Multi-Clustering-Dimensional (MDC) tables, leading to excessive memory consumption. An authenticated attacker with network access and the ability to execute queries can exploit this to cause a denial-of-service (DoS) by exhausting available system memory. IBM has released special builds (interim fixes) for versions 11.5.9 and 12.1.4 to address the issue. As a temporary mitigation, users are advised to avoid the use of MDC tables where possible.
Affected products
- IBM Db2 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-05-21: disclosed: Initial publication by IBM
- 2026-05-21: patched: Special builds released for 11.5.9 and 12.1.4
- 2026-05-27: advisory: NVD publication date