CVE-2025-2518: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1
is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2518?
CVE-2025-2518 is rated as a high severity denial of service vulnerability.
How do I fix CVE-2025-2518?
To fix CVE-2025-2518, update IBM Db2 to version 11.5.10 or later, or 12.1.2 or later.
What causes CVE-2025-2518?
CVE-2025-2518 is caused by the server crashing when processing a specially crafted query.
Which versions of IBM Db2 are affected by CVE-2025-2518?
CVE-2025-2518 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1.
Is a workaround available for CVE-2025-2518?
Currently, there is no documented workaround for CVE-2025-2518; updating to a fixed version is recommended.