CVE-2025-1992

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.
References
Link Resource
https://www.ibm.com/support/pages/node/7232515 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:db2:*:*:*:*:-:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:-:*:*:*
cpe:2.3:a:ibm:db2:12.1.1:*:*:*:-:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:opengroup:unix:-:*:*:*:*:*:*:*

History

20 Aug 2025, 02:23

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:opengroup:unix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:-:*:*:*
cpe:2.3:a:ibm:db2:12.1.1:*:*:*:-:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:-:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7232515 - () https://www.ibm.com/support/pages/node/7232515 - Vendor Advisory
First Time Linux
Microsoft windows
Linux linux Kernel
Opengroup
Microsoft
Opengroup unix
Ibm
Ibm db2

03 Jul 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) IBM Db2 para Linux, UNIX y Windows (incluye DB2 Connect Server) 11.5.0 a 11.5.9 y 12.1.0 a 12.1.1 podría permitir que un usuario autenticado, bajo configuraciones no predeterminadas, provoque una denegación de servicio debido a una liberación insuficiente de memoria asignada después del uso.
Summary (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user, under non default configurations, to cause a denial of service due to insufficient release of allocated memory after usage. (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.

05 May 2025, 17:18

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-05 17:18

Updated : 2025-08-20 02:23


NVD link : CVE-2025-1992

Mitre link : CVE-2025-1992

CVE.ORG link : CVE-2025-1992


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • db2

opengroup

  • unix

microsoft

  • windows
CWE
CWE-401

Missing Release of Memory after Effective Lifetime