Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow flaw in IBM i allows a remote authenticated attacker to access sensitive information. The vulnerability arises from insufficient bounds checking when processing data in the Host Servers, Debug Server, Telnet, and DRDA/DDM components. If successfully exploited, an attacker can read memory contents that may contain confidential data, though the description does not state that arbitrary code execution is achieved.

Affected Systems

Affected products are IBM i releases 7.3 through 7.6, covering the Host Servers, Debug Server (7.6), Telnet (7.6), and DRDA/DDM (7.6). IBM publishes specific PTFs—SJ11101 to SJ11104 for the host servers, SJ10899 for the debug server, SJ11022 for Telnet, and SJ10848 for DRDA/DDM—each addressing this buffer overflow. These updates target the older 7.3, 7.4, 7.5, and 7.6 releases, which are still supported but must be patched to prevent the information leakage.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in widespread exploitation. The flaw requires the attacker to be authenticated to the affected IBM i system to trigger the buffer overflow. Despite the moderate CVSS, the potential for data exposure warrants immediate remediation. The vulnerability is a classic buffer overflow (CWE‑787) and should be mitigated by applying the vendor-supplied patches.

Generated by OpenCVE AI on August 13, 2026 at 21:34 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the latest IBM i PTFs for releases 7.6, 7.5, 7.4, and 7.3 (SJ11101–SJ11104) to address the Host Servers buffer overflow.
  • Apply the additional PTFs for the supporting services—Debug Server (SJ10899), Telnet (SJ11022), and DRDA/DDM (SJ10848)—to ensure all affected components are patched.
  • Restrict or block remote access to Telnet, Debug Server, and DRDA/DDM services until the applicable PTFs are applied, or restrict traffic to trusted IP ranges using firewall rules.

Generated by OpenCVE AI on August 13, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T18:54:18.359Z

Reserved: 2026-07-24T07:23:07.216Z

Link: CVE-2026-16929

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:16.807

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:45:02Z

Weaknesses