Impact
An infinite loop inside IBM i 7.6, 7.5, 7.4, and 7.3 causes a denial of service. A remote attacker can trigger the loop by exploiting a flaw in host services, leading the system to consume resources and become unresponsive. This weakness is an instance of CWE‑835, impacting availability for legitimate users.
Affected Systems
IBM i systems running releases 7.6, 7.5, 7.4, or 7.3 are affected. Vulnerability appears in the host server, debug server, telnet service, and DRDA/DDM interfaces. IBM has issued PTFs—SJ11101 and SJ11097 for 7.6, SJ11102 and SJ11098 for 7.5, SJ11103 and SJ11099 for 7.4, SJ11104 and SJ11100 for 7.3—to address the issue. Unsupported or older releases should be upgraded to a supported and fixed version.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while no EPSS score is available and the vulnerability is not listed in KEV. The attack vector is remote; an attacker over the network can access the vulnerable host services and trigger the denial of service. Because the flaw causes an unbounded loop, its exploitation leads to complete system unavailability until the affected process is restarted or the system is rebooted. Mitigation is time‑critical to preserve business continuity.
OpenCVE Enrichment