Buffer Overflow Vulnerability in IBM Db2 for Linux
CVE-2025-33092

7.8HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
29 July 2025

What is CVE-2025-33092?

IBM Db2 for Linux versions 12.1.0, 12.1.1, and 12.1.2 are affected by a vulnerability that permits a local user to exploit a buffer overflow in the db2fm module. This issue arises from inadequate bounds checking, enabling potential attackers to overwrite memory and execute arbitrary code on the system. It is crucial for users to apply security patches provided by IBM to mitigate this risk.

Affected Version(s)

Db2 Linux 11.5.0 <= 11.5.9

Db2 Linux 12.1.0 <= 12.1.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-33092 : Buffer Overflow Vulnerability in IBM Db2 for Linux