CVE-2026-10535
IBM · Db2
IBM Db2 is vulnerable to a stack-based buffer overflow, which could allow a local attacker to execute arbitrary code or cause a system crash.
Executive summary
A stack-based buffer overflow in IBM Db2 versions 11.5 and 12.1 could allow an attacker to achieve full system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) occurring within the Db2 process. The CVSS vector indicates that the attack requires local access, but it does not require authentication or user interaction to trigger, potentially leading to total confidentiality, integrity, and availability impact.
Business impact
The exploitation of this vulnerability could result in unauthorized access to sensitive database contents, modification of critical business data, or total denial of service. With a CVSS score of 8.4, the risk is classified as High, reflecting the potential for complete system compromise if an attacker gains local access to the host environment.
Remediation
Immediate Action: Download and install the appropriate special build containing the interim fix for either V11.5.9 or V12.1.4 from the IBM Fix Central portal.
Proactive Monitoring: Monitor database and system logs for unexpected process crashes, memory corruption errors, or unusual local activity originating from unauthorized service accounts.
Compensating Controls: Ensure that local access to the Db2 server is strictly restricted to authorized personnel and utilize host-based intrusion detection systems to monitor for anomalous execution patterns.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the severity of this flaw, administrators should prioritize the deployment of the provided special builds. Failure to patch these versions leaves the database server susceptible to local privilege escalation or system-wide disruption.