---
id: CVE-2025-33126
title: >-
  IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1,
  6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1,
  5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3,
  5.1.…
summary: >-
  IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1,
  6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1,
  5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3,
  5.1.…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-131
vendor: ibm
product: db2_high_performance_unload_load
affected:
  - 'db2_high_performance_unload_load >= 5.1.0.0, <= 6.1.0.0'
  - db2_high_performance_unload_load = 6.1.0.1
  - db2_high_performance_unload_load = 6.1.0.2
  - db2_high_performance_unload_load = 6.1.0.3
  - db2_high_performance_unload_load = 6.5.0.0
published: '2025-10-28'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-33126'
references:
  - url: 'https://www.ibm.com/support/pages/node/7249336'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00306
epssPercentile: 0.21374
ingestedAt: '2026-10-08T11:31:27.654Z'
---

## Overview

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size.

## Affected

- `db2_high_performance_unload_load >= 5.1.0.0, <= 6.1.0.0`
- `db2_high_performance_unload_load = 6.1.0.1`
- `db2_high_performance_unload_load = 6.1.0.2`
- `db2_high_performance_unload_load = 6.1.0.3`
- `db2_high_performance_unload_load = 6.5.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
