CVE-2026-18567: IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.
Other sources
IBM Db2 Mirror for i could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11151 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11152 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11153 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11193 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11194 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11195 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11205 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11206 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11207
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to the affected system. The CVSS vector also indicates low privileges are required; remote-only attackers are not in scope based on the provided information.
Which releases are identified as affected?
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are identified as affected.
What is the likely impact of successful exploitation?
Successful exploitation could allow information disclosure. The supplied CVSS vector also indicates a low availability impact, while integrity impact is listed as none.