CVE-2026-18096: IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak
DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.
Other sources
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 12.1 for Linux, UNIX and Windows (includes DB2 Connect Server)to a version that resolves this vulnerability.Fixed in 12.1.5 - Upgrade
Upgrade
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server)to a version that resolves this vulnerability.Fixed in 12.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18096?
The severity of CVE-2026-18096 is rated low at 3.3.
What does CVE-2026-18096 affect?
CVE-2026-18096 affects IBM Db2 12.1.5 for Linux, UNIX, and Windows.
How does CVE-2026-18096 manifest?
CVE-2026-18096 can lead to a denial of service due to a memory leak caused by a local attacker.
Can CVE-2026-18096 be exploited remotely?
CVE-2026-18096 requires local access to exploit the vulnerability.
What is the main impact of CVE-2026-18096?
The main impact of CVE-2026-18096 is the potential for a denial of service.