CVE-2025-33092

7.8

IBM · Db2

IBM Db2 is vulnerable to a stack-based buffer overflow in the db2fm component due to improper bounds checking, which could allow a local user to execute arbitrary code.

Executive summary

A high-severity stack-based buffer overflow in IBM Db2 allows local authenticated users to execute arbitrary code on the underlying system.

Vulnerability

The vulnerability exists in the db2fm component, which performs insufficient bounds checking on user-supplied input. A local user with low privileges can trigger a stack-based buffer overflow to gain unauthorized code execution.

Business impact

The ability for a local user to execute arbitrary code poses a severe risk to data confidentiality, integrity, and availability. With a CVSS score of 7.8, this vulnerability represents a significant threat to the database environment, as an attacker could escalate privileges or compromise sensitive records stored within the system. Successful exploitation could lead to total system compromise and unauthorized access to proprietary business information.

Remediation

Immediate Action: Apply the vendor-provided interim fix or special build available via IBM Fix Central for versions 11.5.9, 12.1.1, and 12.1.2 immediately.

Proactive Monitoring: Monitor system logs for unusual process crashes or unauthorized attempts to access or execute the db2fm binary.

Compensating Controls: Restrict local system access to authorized personnel only and ensure that operating system level hardening is applied to the database host to prevent unauthorized local execution.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Given the potential for full system compromise, organizations should prioritize the deployment of the IBM security updates. Administrators must verify their current Db2 version against the affected list and coordinate with database operations to apply the necessary patches during the next maintenance window to mitigate the risk of local privilege escalation.

More IBM CVEs

Sources