Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
Published: 2026-08-13
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in IBM i’s Simple Mail Transfer Protocol implementation. When an attacker sends specifically crafted SMTP traffic, the overflow can trigger a crash or cause the process to terminate, leading to a denial of service. Because the overflow occurs in native code that handles email headers and data, it may allow the attacker to read or exfiltrate data from memory that is normally protected by the operating‑system boundary, potentially exposing sensitive configuration or user information. The impact is therefore twofold: an attacker can disrupt mail services and may gain access to confidential information stored in the process address space.

Affected Systems

IBM i operating system releases 7.3 through 7.6 are affected. The basis of the fix is the public PTFs listed on IBM’s support portal: for 7.6 the relevant PTFs are SJ11061 and SJ11131; for 7.5 the PTFs are SJ11074 and SJ11129; for 7.4 the PTFs are SJ11083 and SJ11127; for 7.3 the PTFs are SJ11084 and SJ11123. Each release has a dedicated set of patches that must be applied to close the buffer‑overflow bug.

Risk and Exploitability

The CVSS score of 8.6 classifies this flaw as high severity. The EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog, suggesting that no widely‑known exploit has been observed yet. The most likely attack vector is remote, via network reachability to the SMTP service which is commonly exposed on port 25. An attacker with network access and the ability to send mail traffic to the IBM i system could trigger the overflow simply by sending a malformed MAIL FROM, RCPT TO, or DATA command. No local privilege escalation or authentication is required, so any system exposed to the Internet or an untrusted internal network is potentially vulnerable until the appropriate PTFs are installed.

Generated by OpenCVE AI on August 13, 2026 at 20:37 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-TC1 PTF Number(s)PTF Download Link(s)7.6SJ11061 SJ11131 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11061 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11131 7.5SJ11074 SJ11129 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11074 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11129 7.4SJ11083 SJ11127 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11083 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11127 7.3SJ11084 SJ11123 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11084 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11123  https://www.ibm.com/mysupport/s/fix-information IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Determine the exact IBM i release version currently running on the system.
  • Download the appropriate PTF packages for that release from the IBM support site (e.g., SJ11061 and SJ11131 for 7.6, SJ11074 and SJ11129 for 7.5, SJ11083 and SJ11127 for 7.4, or SJ11084 and SJ11123 for 7.3).
  • Install the PTFs following IBM’s patching procedure, which includes validating the download, applying the patches on the target node, and rebooting the system to activate the changes.
  • As a temporary mitigation until the PTFs are applied, consider restricting SMTP service access to trusted IP ranges or disabling the SMTP service entirely if email delivery is not critical.

Generated by OpenCVE AI on August 13, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:40:44.965Z

Reserved: 2026-07-24T01:33:15.634Z

Link: CVE-2026-16815

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:15.187

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:45:02Z

Weaknesses