CVE Vulnerabilities

CVE-2025-36006

Improper Resource Shutdown or Release

Published: Nov 07, 2025 | Modified: Nov 19, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial due to the improper release of resources after use.

Weakness

The product does not release or incorrectly releases a resource before it is made available for re-use.

Affected Software

Name Vendor Start Version End Version
Db2 Ibm 10.5.0.0 (including) 10.5.0.11 (including)
Db2 Ibm 11.1.0 (including) 11.1.4.7 (including)
Db2 Ibm 11.5.0 (including) 11.5.9 (including)
Db2 Ibm 12.1.0 (including) 12.1.3 (including)

Potential Mitigations

  • Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, languages such as Java, Ruby, and Lisp perform automatic garbage collection that releases memory for objects that have been deallocated.

References