CVE-2025-1992

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.
References
Link Resource
https://www.ibm.com/support/pages/node/7232515 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:db2:*:*:*:*:-:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:-:*:*:*
cpe:2.3:a:ibm:db2:12.1.1:*:*:*:-:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:opengroup:unix:-:*:*:*:*:*:*:*

History

20 Aug 2025, 02:23

Type Values Removed Values Added
First Time Ibm db2
Microsoft
Opengroup
Opengroup unix
Microsoft windows
Ibm
Linux
Linux linux Kernel
CPE cpe:2.3:o:opengroup:unix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:-:*:*:*
cpe:2.3:a:ibm:db2:12.1.1:*:*:*:-:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:-:*:*:*
References () https://www.ibm.com/support/pages/node/7232515 - () https://www.ibm.com/support/pages/node/7232515 - Vendor Advisory

03 Jul 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) IBM Db2 para Linux, UNIX y Windows (incluye DB2 Connect Server) 11.5.0 a 11.5.9 y 12.1.0 a 12.1.1 podría permitir que un usuario autenticado, bajo configuraciones no predeterminadas, provoque una denegación de servicio debido a una liberación insuficiente de memoria asignada después del uso.
Summary (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user, under non default configurations, to cause a denial of service due to insufficient release of allocated memory after usage. (en) IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.

05 May 2025, 17:18

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-05 17:18

Updated : 2025-08-20 02:23


NVD link : CVE-2025-1992

Mitre link : CVE-2025-1992

CVE.ORG link : CVE-2025-1992


JSON object : View

Products Affected

opengroup

  • unix

linux

  • linux_kernel

microsoft

  • windows

ibm

  • db2
CWE
CWE-401

Missing Release of Memory after Effective Lifetime