Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.
Published: 2026-08-13
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i versions 7.3 through 7.6 are vulnerable to an error in ASN.1 length processing that allows uninitialized memory to be used. The flaw can be triggered by a remote attacker and results in a denial of service, interrupting services that rely on NetServer and impacting system availability. The weakness is classified as CWE‑908, a failure to properly initialize data before use.

Affected Systems

Affected systems include IBM i releases 7.3, 7.4, 7.5, and 7.6. For each major release IBM provides a pending technical fix (PTF) to address the issue: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6. Organizations running older, unsupported versions are urged to upgrade to a supported and patched release.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity vulnerability. The exploit probability (EPSS) is not provided, but the vulnerability is known to be exploitable over the network by an external party, as the description states a remote attacker can trigger the denial of service. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale exploitation yet. The likely attack vector involves sending specially crafted ASN.1 data to the NetServer component, which processes the length field without proper initialization, causing a crash.

Generated by OpenCVE AI on August 13, 2026 at 21:54 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the IBM i PTF corresponding to your release—MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, and MJ10936 for 7.3
  • Consider limiting NetServer access to trusted networks or disabling the service until the fix is applied as a temporary measure
  • After applying the PTF, verify that NetServer processes complete initialization of ASN.1 structures to confirm the vulnerability is resolved

Generated by OpenCVE AI on August 13, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-908
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:50:51.982Z

Reserved: 2026-07-24T04:17:14.664Z

Link: CVE-2026-16868

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:15.883

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource