CVE-2025-36010
IBM Db2 vulnerability analysis and mitigation

Overview

IBM Db2 for Linux versions 12.1.0, 12.1.1, and 12.1.2 contains a vulnerability that could allow an unauthenticated user to cause a denial of service due to executable segments that are waiting for each other to release a necessary lock. The vulnerability was discovered and disclosed on July 29, 2025, and is tracked as CVE-2025-36010 (IBM Advisory).

Technical details

The vulnerability is classified as CWE-833 (Deadlock) and has received a CVSS v3.1 base score of 6.5 MEDIUM (Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) from IBM Corporation, while the NVD assessment rates it as 7.5 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The issue specifically affects the Linux platform versions, while Unix and Windows versions are not affected (NVD).

Impact

The vulnerability can result in a denial of service condition when executable segments enter a deadlock state while waiting for lock releases. This can affect the availability of the Db2 database service, potentially disrupting business operations that depend on database access (IBM Advisory).

Mitigation and workarounds

For db2 audit-related issues, users can stop db2 audit by removing the policy at database level using 'db2 audit database remove policy' or at instance level using 'db2audit stop'. IBM has released special builds containing interim fixes for versions 12.1.1 and 12.1.2, available through Fix Central. The fix is identified under APAR DT433635 (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36186HIGH7.8
  • IBM Db2IBM Db2
  • cpe:2.3:a:ibm:db2
NoNoNov 07, 2025
CVE-2025-36008MEDIUM6.5
  • IBM Db2IBM Db2
  • cpe:2.3:a:ibm:db2
NoYesNov 07, 2025
CVE-2025-36185MEDIUM5.5
  • IBM Db2IBM Db2
  • cpe:2.3:a:ibm:db2
NoNoNov 07, 2025
CVE-2025-36136MEDIUM5.5
  • IBM Db2IBM Db2
  • cpe:2.3:a:ibm:db2
NoYesNov 07, 2025
CVE-2025-36131MEDIUM4.6
  • IBM Db2IBM Db2
  • cpe:2.3:a:ibm:db2
NoYesNov 07, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management