Impact
IBM i 7.6, 7.5, 7.4, and 7.3 contain a heap buffer overflow that an attacker can trigger remotely. The flaw allows the attacker to corrupt memory in the host server and related services, which can bring the affected processes to a halt. This results in a denial of service, preventing legitimate users from accessing the impacted I/O and networking functions. The weakness is identified as CWE‑787, a classic out‑of‑bounds write attack.
Affected Systems
The vulnerability affects multiple IBM i releases, specifically 7.3, 7.4, 7.5, and 7.6. Within each release, the host servers, debug server, telnet service, and DRDA/DDM interfaces are vulnerable. The IBM PTFs outlined for each release (e.g., SJ11101 to SJ11104 for host servers, SJ10899 for the debug server, SJ11022 for Telnet, and SJ10848 for DRDA/DDM) must be applied to remediate the flaw.
Risk and Exploitability
The CVSS score of 7.5 marks this flaw as high severity, and the lack of an EPSS score suggests limited current exploitation data but does not negate the risk. Because the attack vector is remote and does not require authenticated access, any system exposing the affected services to untrusted networks or users is at risk. The flaw is not listed in the CISA KEV catalog, yet the possibility of denial of service could still disrupt mission‑critical operations. Promptly addressing the flaw with the IBM‑issued PTFs and/or upgrading to a supported release is essential to mitigate the threat.
OpenCVE Enrichment