Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow in IBM i versions 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to execute arbitrary code. The flaw is present across several IBM i host services, including Host Servers, Debug Server, Telnet, and DRDA/DDM. An attacker who can authenticate to the system and trigger the overflow can take control of the affected process, potentially compromising the entire platform. The weakness is identified as CWE‑787 – Buffer Overflow, which directly jeopardizes the integrity and availability of the system.

Affected Systems

IBM i platforms running releases 7.6‑SS1, 7.5‑SS1, 7.4‑SS1 and 7.3‑SS1 are affected. For each release, IBM provides specific Product Fix Technology (PTF) numbers to remediate the flaw: Host Servers PTFs include SJ11101 and SJ11097 for 7.6, SJ11102 and SJ11098 for 7.5, SJ11103 and SJ11099 for 7.4, and SJ11104 and SJ11100 for 7.3. Additional PTFs are required for other services: Debug Server requires SJ10899, Telnet requires SJ11022, and DRDA/DDM requires SJ10848.

Risk and Exploitability

The CVSS score of 8.8 indicates very high severity; the flaw can be abused by any authenticated user with sufficient privileges to produce a buffer overflow. Although an EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests no current public exploits are tracked, but the high severity and confirmed resource for remediation warrant immediate attention. IBM recommends addressing the vulnerability promptly to prevent potential compromise of confidentiality, integrity, and system availability.

Generated by OpenCVE AI on August 13, 2026 at 21:34 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Confirm the IBM i release and determine which Host Servers PTFs (SJ11101, SJ11097, SJ11102, SJ11098, SJ11103, SJ11099, SJ11104, SJ11100) apply to your installation and download them from IBM’s support site.
  • Apply the Debug Server PTF SJ10899, the Telnet PTF SJ11022, and the DRDA/DDM PTF SJ10848 to cover all vulnerable services.
  • Reboot the system to ensure the PTFs take effect.

Generated by OpenCVE AI on August 13, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T18:56:07.766Z

Reserved: 2026-07-24T20:20:03.940Z

Link: CVE-2026-17223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:19.097

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:30:10Z

Weaknesses