Impact
The vulnerability arises from an improper loop termination in IBM i 7.6, 7.5, 7.4, and 7.3, allowing a remote attacker to trigger an infinite loop that consumes system resources and results in denial of service. It is classified as CWE-835. The flaw can disable Host Server, Debug Server, Telnet, or DRDA/DDM services, but it does not affect data confidentiality or integrity.
Affected Systems
Affected systems are IBM i Release 7.6, 7.5, 7.4, and 7.3, running any of the Host Server, Debug Server, Telnet, or DRDA/DDM services. The issue is present in IBM i version 7.3 through 7.6 and is addressed by the PTFs listed in the advisory. Unsupported versions should be upgraded or patched. The documented workarounds advise upgrading to a fixed, supported release.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity for a denial of service. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, suggesting no confirmed real‑world exploitation yet. However, the remote nature and impact on critical services mean that an attacker could interrupt business processes by exploiting the infinite loop, especially if the services are exposed to external networks.
OpenCVE Enrichment