Impact
A stack-based buffer overflow in the Simple Mail Transfer Protocol implementation of IBM i 7.6, 7.5, 7.4, and 7.3 can be triggered by a remote authenticated attacker, leading to a denial of service. The vulnerability is classified as CWE-787: Improper Bounds Checking. Exploitation consumes memory or corrupts the stack, causing the affected system to become unresponsive or to restart, compromising availability.
Affected Systems
IBM i operating systems—versions 7.6 (Release 5770‑TC1), 7.5, 7.4, and 7.3—are impacted. IBM has released a series of Product Fixes (PTFs) for these releases, including SJ11061 and SJ11131 for 7.6; SJ11074 and SJ11129 for 7.5; SJ11083 and SJ11127 for 7.4; and SJ11084 and SJ11123 for 7.3. Systems running unsupported or older releases are also advised to upgrade.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity risk. EPSS is not available, so the exact likelihood of exploitation cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog and has no known public exploits yet. The attack requires remote authenticated access, suggesting the attacker must obtain valid credentials. Given these conditions, the overall risk is moderate but still significant for services that rely on uninterrupted mail processing.
OpenCVE Enrichment