Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service via buffer overflow
Action: Patch Immediately
AI Analysis

Impact

IBM i versions 7.3 through 7.6 are vulnerable to a remote attacker exploiting a buffer overflow that can lead to a denial of service and compromise system integrity. The flaw is disclosed as a classic out‑of‑bounds write (CWE‑787) and can be triggered by a malicious NFS client. Successful exploitation can cause the affected system to crash or become unresponsive, potentially allowing an attacker to disrupt services or gain further lateral movement within the environment if systemic integrity is undermined.

Affected Systems

Affected systems include IBM i 7.6, 7.5, 7.4, and 7.3 operating on any architecture that utilizes NFS. The list of impacted releases is specifically indicated by the provided PTFs: 7.6 - SJ11320, 7.5 - SJ11319, 7.4 - SJ11318, and 7.3 - SJ11317. IBM recommends non‑supported versions be upgraded to a supported release with the patches applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity condition. No EPSS value is available, so concrete exploitation likelihood cannot be quantified from the data. The vulnerability is not currently listed in CISA KEV, meaning there is no known active exploitation campaign catalogued. The attack vector is inferred to be remote via NFS clients, requiring network access to the NFS service but not privileged local access.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11320 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11320 7.5SJ11319 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11319 7.4SJ11318 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11318 7.3SJ11317 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11317 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770‑SS1 patch, or apply the specific PTF for the running release (SJ11320 for 7.6, SJ11319 for 7.5, SJ11318 for 7.4, SJ11317 for 7.3).
  • Upgrade the system to the latest supported IBM i release that includes the fix for this buffer overflow.
  • If an immediate patch or upgrade is not possible, temporarily disable or restrict the NFS service to prevent remote triggering of the vulnerability until the remediation can be applied.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
Title IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:32:45.856Z

Reserved: 2026-07-24T19:32:36.305Z

Link: CVE-2026-17207

cve-icon Vulnrichment

Updated: 2026-09-04T17:32:40.107Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:53.020

Modified: 2026-09-08T17:19:42.270

Link: CVE-2026-17207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:45:03Z

Weaknesses