Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i 7.6, 7.5, 7.4, and 7.3 contain a heap buffer overflow that an attacker can trigger remotely. The flaw allows the attacker to corrupt memory in the host server and related services, which can bring the affected processes to a halt. This results in a denial of service, preventing legitimate users from accessing the impacted I/O and networking functions. The weakness is identified as CWE‑787, a classic out‑of‑bounds write attack.

Affected Systems

The vulnerability affects multiple IBM i releases, specifically 7.3, 7.4, 7.5, and 7.6. Within each release, the host servers, debug server, telnet service, and DRDA/DDM interfaces are vulnerable. The IBM PTFs outlined for each release (e.g., SJ11101 to SJ11104 for host servers, SJ10899 for the debug server, SJ11022 for Telnet, and SJ10848 for DRDA/DDM) must be applied to remediate the flaw.

Risk and Exploitability

The CVSS score of 7.5 marks this flaw as high severity, and the lack of an EPSS score suggests limited current exploitation data but does not negate the risk. Because the attack vector is remote and does not require authenticated access, any system exposing the affected services to untrusted networks or users is at risk. The flaw is not listed in the CISA KEV catalog, yet the possibility of denial of service could still disrupt mission‑critical operations. Promptly addressing the flaw with the IBM‑issued PTFs and/or upgrading to a supported release is essential to mitigate the threat.

Generated by OpenCVE AI on August 13, 2026 at 20:55 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM PTFs SJ11101, SJ11102, SJ11103, SJ11104, and SJ11100 to the host servers for all affected releases.
  • Install the debug server PTF SJ10899, the Telnet PTF SJ11022, and the DRDA/DDM PTF SJ10848 on the corresponding server components.
  • Upgrade all IBM i installations to the latest supported release that contains the fixed code, and if an upgrade is not immediately possible, disable or restrict external access to the vulnerable services such as Telnet, host servers, and DRDA/DDM to reduce exposure.

Generated by OpenCVE AI on August 13, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T18:51:10.904Z

Reserved: 2026-07-24T08:38:34.338Z

Link: CVE-2026-16982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:17.377

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:00:06Z

Weaknesses