Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Published: 2026-08-12
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the Line Printer Daemon component of IBM i. An attacker able to send a crafted request can cause memory corruption that allows arbitrary code execution. The effect is that the attacker can run code with the privileges of the LPD service, potentially taking full control of the affected system. This weakness corresponds to CWE‑787.

Affected Systems

Affected versions include IBM i 7.6, 7.5, 7.4, and 7.3. IBM lists the fix via PTFs: SJ10872 for 7.6, SJ10896 for 7.5, SJ10929 for 7.4, and SJ10930 for 7.3. Users on any unsupported or older releases should consider upgrading to a supported, patched release, as recommended by IBM.

Risk and Exploitability

The CVSS score is 9.8, indicating critical severity. Because the analysis does not provide an EPSS value, the exploit probability is considered unknown, yet the lack of KEV listing does not diminish the urgency. The vulnerability can be exploited remotely, likely through the standard LPD socket interface, with no authentication required. Prompt patching is therefore necessary.

Generated by OpenCVE AI on August 12, 2026 at 22:43 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10872 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10872 7.5SJ10896 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10896 7.4SJ10929 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10929 7.3SJ10930 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10930 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and apply the IBM PTFs for your release (SJ10872 for 7.6, SJ10896 for 7.5, SJ10929 for 7.4, SJ10930 for 7.3) following IBM’s instructions.
  • If the system is on an unsupported IBM i version, upgrade to a supported, patched release before applying patches.
  • After installing the patches, restart the Line Printer Daemon service to ensure the changes take effect.
  • Monitor Line Printer Daemon traffic and system logs for any anomalous activity.

Generated by OpenCVE AI on August 12, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Title IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon []
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T18:55:18.071Z

Reserved: 2026-07-24T20:07:39.903Z

Link: CVE-2026-17218

cve-icon Vulnrichment

Updated: 2026-08-12T18:55:08.456Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T18:17:25.867

Modified: 2026-08-12T20:53:43.330

Link: CVE-2026-17218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:45:10Z

Weaknesses