Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.
Published: 2026-08-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i version 7.6, 7.5, 7.4 and 7.3 contain a remote buffer overflow that allows an attacker to trigger a denial of service and alter authentication metadata. The buffer overflow occurs when the system processes input from network services without proper bounds checking, leading to crash or modification of critical security state. As a result, an attacker could temporarily deny legitimate users from accessing the system and potentially tamper with authentication credentials or logs.

Affected Systems

The affected modules include Host Servers, Debug Server, Telnet, and DRDA/DDM on IBM i installations running releases 7.6, 7.5, 7.4, or 7.3. The vendor has published specific Program Temporary Fix (PTF) numbers for each subsystem—SJ11101, SJ11102, SJ11103, SJ11104, SJ11100 for Host Servers; SJ10899 for the Debug Server; SJ11022 for Telnet; and SJ10848 for DRDA/DDM. Systems running unsupported versions should upgrade to a supported release with the fixes applied.

Risk and Exploitability

With a CVSS score of 8.2 this vulnerability is classified as high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. Nonetheless, the attack vector is inferred to be remote and involves exploitation of exposed network services. An attacker with network reach to the affected IBM i system can send crafted input to trigger the overflow, causing a service interruption and compromising authentication data. The risk remains significant due to the critical nature of authentication metadata and the potential for denial of service in enterprise environments.

Generated by OpenCVE AI on August 13, 2026 at 20:55 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the Host Servers PTFs: SJ11101, SJ11102, SJ11103, SJ11104 and SJ11100 to all affected releases.
  • Apply the Debug Server PTF SJ10899 to all affected releases.
  • Apply the Telnet PTF SJ11022 to all affected releases.
  • Apply the DRDA/DDM PTF SJ10848 to all affected releases.
  • For systems running unsupported or older releases, upgrade to the latest supported release of IBM i that includes these patches.
  • Ensure all inputs to USB, Telnet, Debug and DRDA/DDM services are validated and bounded, following best practice for avoiding buffer overflows.

Generated by OpenCVE AI on August 13, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-120
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:26:14.893Z

Reserved: 2026-07-24T20:12:27.469Z

Link: CVE-2026-17220

cve-icon Vulnrichment

Updated: 2026-08-13T19:24:49.442Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T19:17:18.810

Modified: 2026-08-17T14:57:53.307

Link: CVE-2026-17220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:00:06Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')