IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
2025-07-29T19:15:45.487
2025-08-06T19:37:37.587
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | db2 | 12.1.0 | Yes |
| Application | ibm | db2 | 12.1.1 | Yes |
| Application | ibm | db2 | 12.1.2 | Yes |