CVE-2026-10534: IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser
Db2 is vulnerable to buffer overflow in the IXF IMPORT parser.
Other sources
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 (IXF IMPORT parser)to a version that resolves this vulnerability.Fixed in 12.1.4Patch Security Update #88454 - Upgrade
Upgrade
IBM Db2 (IXF IMPORT parser)to a version that resolves this vulnerability.Fixed in 12.1.5Patch Security Update #88454 - Upgrade
Upgrade
IBM Db2 (IXF IMPORT parser)to a version that resolves this vulnerability.Fixed in 11.5.9Patch Security Update #88454
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10534?
The severity of CVE-2026-10534 is high, with a CVSS score of 8.4.
How do I fix CVE-2026-10534?
To fix CVE-2026-10534, upgrade IBM Db2 to version 11.5.10 or later, or 12.1.6 or later.
What software is affected by CVE-2026-10534?
CVE-2026-10534 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5.
What type of vulnerability is CVE-2026-10534?
CVE-2026-10534 is a buffer overflow vulnerability in the IXF IMPORT parser.
When was CVE-2026-10534 published?
CVE-2026-10534 was published on August 7, 2026.