Impact
IBM i versions 7.3 through 7.6 are vulnerable to a remote attacker exploiting a buffer overflow that can lead to a denial of service and compromise system integrity. The flaw is disclosed as a classic out‑of‑bounds write (CWE‑787) and can be triggered by a malicious NFS client. Successful exploitation can cause the affected system to crash or become unresponsive, potentially allowing an attacker to disrupt services or gain further lateral movement within the environment if systemic integrity is undermined.
Affected Systems
Affected systems include IBM i 7.6, 7.5, 7.4, and 7.3 operating on any architecture that utilizes NFS. The list of impacted releases is specifically indicated by the provided PTFs: 7.6 - SJ11320, 7.5 - SJ11319, 7.4 - SJ11318, and 7.3 - SJ11317. IBM recommends non‑supported versions be upgraded to a supported release with the patches applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity condition. No EPSS value is available, so concrete exploitation likelihood cannot be quantified from the data. The vulnerability is not currently listed in CISA KEV, meaning there is no known active exploitation campaign catalogued. The attack vector is inferred to be remote via NFS clients, requiring network access to the NFS service but not privileged local access.
OpenCVE Enrichment