CVE-2025-36442: IBM Db2 Denial of Service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36442?
CVE-2025-36442 is categorized as a denial of service vulnerability with potential impacts on system availability.
How do I fix CVE-2025-36442?
To mitigate CVE-2025-36442, upgrading to a patched version of IBM Db2 that resolves the issue is recommended.
What versions of IBM Db2 are affected by CVE-2025-36442?
CVE-2025-36442 affects IBM Db2 for Linux, UNIX, and Windows versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.3.
What kind of attack does CVE-2025-36442 relate to?
CVE-2025-36442 relates to a denial of service attack where the server may crash due to a specially crafted query with XML columns.
Is there any workaround for CVE-2025-36442?
Currently, the only reliable solution for CVE-2025-36442 is to apply the recommended updates or patches provided by IBM.