IBM Db2 Denial-of-Service Vulnerability When Copying Large XML Tables

Vulnerability

A denial-of-service vulnerability has been identified in IBM Db2 for Linux, UNIX, and Windows, including DB2 Connect Server, versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3. This vulnerability could allow a local user to cause a denial-of-service condition by copying large tables containing XML data, due to improper resource allocation.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or unavailable.

Remediation

Users can download a special build containing the interim fix for this issue from Fix Central. For Db2 version 11.5, the special build #66394 or later is available. For Db2 version 12.1, the special build #72296 or later is available. Instructions for downloading these special builds can be found on the IBM Support page.

Added: Jan 30, 2026, 10:34 PM
Updated: Jan 30, 2026, 10:34 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
3.1
remediation
7.7
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.