Impact
An out-of-bounds read in the NetServer component of IBM i can be triggered by a remote attacker, causing the operating system to crash or restart. This results in a denial of service that can interrupt business operations. The vulnerability stems from improper bounds checking when processing network requests, classified under CWE‑125.
Affected Systems
IBM i versions 7.3, 7.4, 7.5 and 7.6 are impacted. The corresponding PTFs are MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5 and MJ10939 for 7.6. These patches address the uninitialized memory read in NetServer. Any system still running one of these releases should apply the related fix or upgrade to a newer, supported release that contains the remediation.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Because the attack requires remote network access to the NetServer service and the EPSS score is currently unavailable, the likelihood of exploitation is uncertain, though the existence of a DoS impact motivates immediate action. The vulnerability is not listed in the CISA KEV catalog, but IBM advises users to address it immediately.
OpenCVE Enrichment