Impact
IBM i versions 7.3 through 7.6 are vulnerable to an error in ASN.1 length processing that allows uninitialized memory to be used. The flaw can be triggered by a remote attacker and results in a denial of service, interrupting services that rely on NetServer and impacting system availability. The weakness is classified as CWE‑908, a failure to properly initialize data before use.
Affected Systems
Affected systems include IBM i releases 7.3, 7.4, 7.5, and 7.6. For each major release IBM provides a pending technical fix (PTF) to address the issue: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6. Organizations running older, unsupported versions are urged to upgrade to a supported and patched release.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The exploit probability (EPSS) is not provided, but the vulnerability is known to be exploitable over the network by an external party, as the description states a remote attacker can trigger the denial of service. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale exploitation yet. The likely attack vector involves sending specially crafted ASN.1 data to the NetServer component, which processes the length field without proper initialization, causing a crash.
OpenCVE Enrichment