CVE-2026-6052
Analyzed Analyzed - Analysis Complete
Memory Exhaustion in IBM Db2 Due to MDC Table Queries

Publication date: 2026-05-27

Last updated on: 2026-05-28

Assigner: IBM Corporation

Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-05-28
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ibm db2 From 11.5.0 (inc) to 11.5.9 (inc)
ibm db2 From 12.1.0 (inc) to 12.1.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The vulnerability in IBM Db2 (CVE-2026-6052) primarily causes denial of service due to resource exhaustion when executing certain queries with MDC tables. There is no information provided about any impact on data confidentiality or integrity.

Since the vulnerability does not affect data confidentiality or integrity, it does not directly indicate a compliance risk with standards like GDPR or HIPAA, which focus on protecting personal and sensitive data.

However, denial of service could indirectly affect availability requirements under such regulations, potentially impacting compliance if critical systems become unavailable.

Executive Summary

CVE-2026-6052 is a vulnerability in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 that causes the system to run out of memory when executing certain queries involving Multi-Dimensional Clustering (MDC) tables.

Impact Analysis

The primary impact of this vulnerability is a denial of service condition caused by resource exhaustion, specifically running out of memory during query execution. This can disrupt database availability and affect applications relying on the Db2 database.

Detection Guidance

IBM has not provided detailed replication or detection steps for this vulnerability to prevent potential exploitation.

Mitigation Strategies

To mitigate the vulnerability, IBM recommends applying interim fixes available through special builds on Fix Central for the affected Db2 versions.

As a workaround, users should avoid using Multi-Dimensional Clustering (MDC) tables until a permanent fix is applied.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6052. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart