CVE-2026-17177

7.5

IBM · Db2 Mirror for i

IBM Db2 Mirror for i is susceptible to an uncontrolled recursion vulnerability, which could allow an unauthenticated remote attacker to cause a denial of service.

Executive summary

An uncontrolled recursion flaw in IBM Db2 Mirror for i 7.4, 7.5, and 7.6 allows unauthenticated remote attackers to trigger a denial of service condition.

Vulnerability

The vulnerability is identified as CWE-674, Uncontrolled Recursion. An unauthenticated attacker can exploit this by sending specifically crafted requests that exhaust system resources, leading to service instability or a crash.

Business impact

This vulnerability carries a CVSS score of 7.5, reflecting its high impact on system availability. Successful exploitation would result in a denial of service, effectively halting database mirroring operations and causing significant business disruption for critical enterprise applications relying on Db2 Mirror.

Remediation

Immediate Action: Apply the vendor-provided PTF updates immediately: SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6 via the IBM Fix Central portal.

Proactive Monitoring: Monitor system resource utilization, specifically CPU and memory spikes, which may indicate an ongoing attempt to trigger the recursive loop.

Compensating Controls: Implement rate limiting or request validation at the network perimeter to filter out malformed or excessive traffic directed toward the Db2 Mirror service.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical nature of database availability, administrators should treat this update with high priority. Promptly installing the vendor patches is required to prevent potential service outages caused by this recursion vulnerability.

More IBM CVEs