Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An infinite loop inside IBM i 7.6, 7.5, 7.4, and 7.3 causes a denial of service. A remote attacker can trigger the loop by exploiting a flaw in host services, leading the system to consume resources and become unresponsive. This weakness is an instance of CWE‑835, impacting availability for legitimate users.

Affected Systems

IBM i systems running releases 7.6, 7.5, 7.4, or 7.3 are affected. Vulnerability appears in the host server, debug server, telnet service, and DRDA/DDM interfaces. IBM has issued PTFs—SJ11101 and SJ11097 for 7.6, SJ11102 and SJ11098 for 7.5, SJ11103 and SJ11099 for 7.4, SJ11104 and SJ11100 for 7.3—to address the issue. Unsupported or older releases should be upgraded to a supported and fixed version.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while no EPSS score is available and the vulnerability is not listed in KEV. The attack vector is remote; an attacker over the network can access the vulnerable host services and trigger the denial of service. Because the flaw causes an unbounded loop, its exploitation leads to complete system unavailability until the affected process is restarted or the system is rebooted. Mitigation is time‑critical to preserve business continuity.

Generated by OpenCVE AI on August 13, 2026 at 20:53 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and install the latest PTFs for your IBM i release (e.g., SJ11101/SJ11097 for 7.6, SJ11102/SJ11098 for 7.5, SJ11103/SJ11099 for 7.4, SJ11104/SJ11100 for 7.3).
  • If your system runs an unsupported release, upgrade to the latest supported IBM i version before applying the PTFs.
  • Disable or restrict unused protocols such as the debug server, telnet, or DRDA/DDM if they are not required for your environment.

Generated by OpenCVE AI on August 13, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-835
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:33:44.387Z

Reserved: 2026-07-24T09:42:46.019Z

Link: CVE-2026-17004

cve-icon Vulnrichment

Updated: 2026-08-13T19:33:30.683Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:17.660

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:00:06Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')