CVE-2026-86093
largeStack-Based Buffer Overflow RCE in IBM Db2 DRDA Clients
IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a stack-based buffer overflow (CWE-121) in the handling of DRDA protocol data, in which user-controlled data received from a server is copied into a fixed-size stack buffer without bounds checking. The flaw is triggered on the client side: an attacker who can control or impersonate the DRDA server endpoint a Db2 client connects to — for example via a rogue or compromised server, DNS hijack, or man-in-the-middle position — sends crafted server responses that overflow the buffer. Successful exploitation allows arbitrary command execution on the machine running the Db2 client, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.5 high, network vector with high attack complexity). Any organization running affected Db2 releases whose client components (e.g., CLI/ODBC/JDBC applications or command-line sessions) connect to DRDA servers is potentially affected, but practical exploitation requires control of the server endpoint. There is no known public proof-of-concept, no CISA KEV listing, and no reports of in-the-wild exploitation at this time.
What to do: Check IBM's security bulletin for this CVE and upgrade affected Db2 releases out of the vulnerable ranges (beyond 11.5.9 and 12.1.5) once IBM publishes fixed builds. Until patched, restrict Db2 clients to known-trusted DRDA server endpoints, prefer TLS-protected connections with server verification, and inventory which applications use Db2 client connectivity (CLI/ODBC/JDBC) and which remote DRDA destinations they contact. Treat network paths vulnerable to interception and connections to non-Db2 or third-party DRDA servers as higher risk.
| IBM Db2 | 11.5.0 through 11.5.9 |
| IBM Db2 | 12.1.0 through 12.1.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
- Vendors
- ibm
- Products
- db2
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.