PatchSiren cyber security CVE debrief
CVE-2026-6053 IBM CVE debrief
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a denial-of-service vulnerability triggered when a specially crafted query is executed against range-partitioned tables. The vulnerability, published 2026-05-27, carries a CVSS 3.1 score of 5.5 (MEDIUM) with an attack vector requiring local access and low privileges. The underlying weakness is categorized as CWE-770 (Allocation of Resources Without Limits or Throttling), suggesting the crafted query may cause excessive resource consumption leading to service disruption. No known exploitation in the wild or ransomware campaign use has been documented. IBM has published a security bulletin with remediation guidance.
- Vendor
- IBM
- Product
- Db2
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-27
Who should care
Database administrators managing IBM Db2 11.5.x or 12.1.x deployments, security teams responsible for database infrastructure availability, and compliance officers tracking patch status for medium-severity vulnerabilities in data platforms
Technical summary
The vulnerability exists in IBM Db2's handling of queries against range-partitioned tables. A specially crafted query can trigger a denial-of-service condition. The attack requires local access and low privileges but no user interaction. The high availability impact (A:H) with no confidentiality or integrity effects suggests a crash or hang condition rather than data corruption or unauthorized access.
Defensive priority
medium
Recommended defensive actions
- Review IBM security bulletin for available fix packs or patches for affected Db2 versions
- Audit database query patterns for anomalous activity targeting range-partitioned tables
- Implement query resource limits and timeout controls as compensating controls where patching is delayed
- Monitor Db2 instance availability and resource utilization for signs of exhaustion attacks
- Restrict database access to authorized users with least-privilege principles given the low privilege requirement
Evidence notes
Vulnerability confirmed through IBM PSIRT disclosure and NVD entry. CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H indicates local attack with high availability impact. CWE-770 classification points to resource exhaustion as the likely mechanism.
Official resources
-
CVE-2026-6053 CVE record
CVE.org
-
CVE-2026-6053 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-27T14:17:34.633Z