Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i versions 7.6, 7.5, 7.4, and 7.3 contain an integer error that occurs when the system processes DRDA large‑object headers. An attacker who can send a malicious DRDA request may trigger this error, causing the database service to terminate or restart and resulting in a denial of service. The flaw is classified as CWE‑190, indicating an integer overflow/underflow that can disrupt normal operation.

Affected Systems

Affected products are IBM i systems running Release 7.6, 7.5, 7.4, or 7.3. These versions are identified by the cpe strings for IBM:i 7.3 through 7.6.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation, but the remote nature of the attack vector and the impact to service availability warrant monitoring. An attacker would need network access to the DRDA interface and could exploit the integer error by sending a crafted large‑object header, which may require some knowledge of the DB2/DRDA protocol. Because the error can only cause a temporary service interruption, the damage is limited to availability disruption rather than data breach.

Generated by OpenCVE AI on August 13, 2026 at 22:08 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 7.5SJ10849 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10849 7.4SJ10850 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10850 7.3SJ10851 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10851 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-SS1 updates via the following PTFs: for 7.6 use SJ10848, for 7.5 use SJ10849, for 7.4 use SJ10850, and for 7.3 use SJ10851.
  • If the DRDA interface is not required, disable it or restrict traffic to trusted hosts to reduce exposure.
  • Continuously monitor for abnormal DRDA connections and ensure that a logging mechanism captures large‑object header traffic for audit.

Generated by OpenCVE AI on August 13, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.
Title IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM
First Time appeared Ibm
Ibm i
Weaknesses CWE-190
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:28:11.670Z

Reserved: 2026-07-24T19:57:54.753Z

Link: CVE-2026-17216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:42.420

Modified: 2026-08-13T21:17:42.420

Link: CVE-2026-17216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:15:03Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound