Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read in the NetServer component of IBM i can be triggered by a remote attacker, causing the operating system to crash or restart. This results in a denial of service that can interrupt business operations. The vulnerability stems from improper bounds checking when processing network requests, classified under CWE‑125.

Affected Systems

IBM i versions 7.3, 7.4, 7.5 and 7.6 are impacted. The corresponding PTFs are MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5 and MJ10939 for 7.6. These patches address the uninitialized memory read in NetServer. Any system still running one of these releases should apply the related fix or upgrade to a newer, supported release that contains the remediation.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. Because the attack requires remote network access to the NetServer service and the EPSS score is currently unavailable, the likelihood of exploitation is uncertain, though the existence of a DoS impact motivates immediate action. The vulnerability is not listed in the CISA KEV catalog, but IBM advises users to address it immediately.

Generated by OpenCVE AI on August 13, 2026 at 21:48 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the NetServer PTFs MJ10936 through MJ10939 for releases 7.3 to 7.6 as published in the IBM support catalog.
  • If the system runs a different, unsupported IBM i release, upgrade to the latest supported release that includes the NetServer fix.
  • Limit or disable the NetServer service on hosts that do not require it, or restrict inbound traffic to the NetServer ports using firewalls or network segmentation.

Generated by OpenCVE AI on August 13, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:27:43.664Z

Reserved: 2026-07-24T19:47:30.179Z

Link: CVE-2026-17212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:42.290

Modified: 2026-08-13T21:17:42.290

Link: CVE-2026-17212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses