Impact
The vulnerability is an out‑of‑bounds write in the Line Printer Daemon component of IBM i. An attacker able to send a crafted request can cause memory corruption that allows arbitrary code execution. The effect is that the attacker can run code with the privileges of the LPD service, potentially taking full control of the affected system. This weakness corresponds to CWE‑787.
Affected Systems
Affected versions include IBM i 7.6, 7.5, 7.4, and 7.3. IBM lists the fix via PTFs: SJ10872 for 7.6, SJ10896 for 7.5, SJ10929 for 7.4, and SJ10930 for 7.3. Users on any unsupported or older releases should consider upgrading to a supported, patched release, as recommended by IBM.
Risk and Exploitability
The CVSS score is 9.8, indicating critical severity. Because the analysis does not provide an EPSS value, the exploit probability is considered unknown, yet the lack of KEV listing does not diminish the urgency. The vulnerability can be exploited remotely, likely through the standard LPD socket interface, with no authentication required. Prompt patching is therefore necessary.
OpenCVE Enrichment