Impact
A flaw in IBM i 7.6, 7.5, 7.4, and 7.3 allows a remote attacker to send specially crafted packets that contain zero‑length TCP options, forcing the target to enter a state that leads to a denial of service. The vulnerability is classified as CWE‑835, indicating an infinite‑loop or resource‑exhaustion condition that results in service unavailability.
Affected Systems
The defect affects IBM i systems running versions 7.6, 7.5, 7.4, and 7.3. IBM provides patch teams (PTFs) MJ10911 for 7.6, MJ10912 for 7.5, MJ10913 for 7.4, and MJ10914 for 7.3, which address the issue.
Risk and Exploitability
The CVSS score of 7.5 points to a high severity level. Exploitation does not require authentication and can be carried out by any external host capable of sending TCP packets with zero‑length options. Although an EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the potential for widespread denial of service and the lack of immediate mitigation make the risk significant. Remediation is essential, and systems still running supported or unsupported IBM i versions should be patched or upgraded promptly.
OpenCVE Enrichment