CVE-2023-26022: IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory occurs using the DBMSOUTPUT module.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-26022?
CVE-2023-26022 is a vulnerability in IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) that can lead to a denial of service by causing the server to crash when an Out of Memory occurs using the DBMS_OUTPUT module.
How severe is CVE-2023-26022?
CVE-2023-26022 has a severity value of 7.5, which is considered high.
Which versions of IBM Db2 are affected by CVE-2023-26022?
CVE-2023-26022 affects IBM Db2 versions 10.5, 11.1.4, 11.5, 11.1, and 11.5.8.
How can I fix CVE-2023-26022?
To fix CVE-2023-26022, apply the necessary patches and updates provided by IBM for the affected versions of Db2.
Where can I find more information about CVE-2023-26022?
You can find more information about CVE-2023-26022 on the IBM X-Force ID page (https://exchange.xforce.ibmcloud.com/vulnerabilities/247868) and the IBM support page (https://www.ibm.com/support/pages/node/6985669).