CVE-2025-36070: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap may occur when selecting from certain types of tables.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as a trap may occur when selecting from certain types of tables.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36070?
CVE-2025-36070 is classified as a denial of service vulnerability that can disrupt IBM Db2 operations.
How do I fix CVE-2025-36070?
To fix CVE-2025-36070, you should upgrade to IBM Db2 versions 11.5.10 or 12.1.4 or later.
What versions of IBM Db2 are affected by CVE-2025-36070?
CVE-2025-36070 affects IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3.
What impact does CVE-2025-36070 have on IBM Db2?
CVE-2025-36070 can cause a denial of service, potentially leading to system downtime when selecting from certain table types.
Is there a workaround for CVE-2025-36070?
There are currently no documented workarounds for CVE-2025-36070; upgrading is the recommended mitigation.