CVE-2025-36123: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service when copying large table containing XML data due to improper allocation of system resources.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause a denial of service when copying large table containing XML data due to improper allocation of system resources.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36123?
CVE-2025-36123 is classified as a denial of service vulnerability which can severely impact the availability of IBM Db2.
How do I fix CVE-2025-36123?
To mitigate CVE-2025-36123, ensure you update IBM Db2 to the latest version beyond 11.5.9 and 12.1.3.
Which versions of IBM Db2 are affected by CVE-2025-36123?
CVE-2025-36123 affects IBM Db2 versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3.
What causes the vulnerability identified as CVE-2025-36123?
CVE-2025-36123 is caused by improper allocation of system resources when handling large tables with XML data, leading to potential denial of service.
Can CVE-2025-36123 be exploited by remote attackers?
CVE-2025-36123 requires a local user to exploit the vulnerability, thus it is not remotely exploitable.