Executive brief
IBM Db2 is a database management system used by organizations to store and analyze large amounts of data. A vulnerability has been identified where the system can be forced into an infinite loop or crash when processing specifically formatted database queries. This could allow a user to cause a denial-of-service, making the database unavailable for legitimate business operations.
Technical details
IBM Db2 versions 11.5 and 12.1 are susceptible to a denial of service vulnerability (CWE-835) during the statement compilation phase. The root cause is a 'trap' or infinite loop triggered when the database engine processes specially crafted SQL statements that include specific subquery structures. An attacker with the ability to submit queries to the database can exploit this to exhaust system resources or cause a service hang. The vulnerability affects both Client and Server components across all supported platforms (Linux, AIX, Windows). IBM has released special builds for versions 11.5.9 and 12.1.4 to remediate the issue.
Affected products
- IBM Db2 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-07-10: disclosed: Initial publication by IBM
- 2026-07-17: advisory: NVD publication date