Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an improper loop termination in IBM i 7.6, 7.5, 7.4, and 7.3, allowing a remote attacker to trigger an infinite loop that consumes system resources and results in denial of service. It is classified as CWE-835. The flaw can disable Host Server, Debug Server, Telnet, or DRDA/DDM services, but it does not affect data confidentiality or integrity.

Affected Systems

Affected systems are IBM i Release 7.6, 7.5, 7.4, and 7.3, running any of the Host Server, Debug Server, Telnet, or DRDA/DDM services. The issue is present in IBM i version 7.3 through 7.6 and is addressed by the PTFs listed in the advisory. Unsupported versions should be upgraded or patched. The documented workarounds advise upgrading to a fixed, supported release.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity for a denial of service. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, suggesting no confirmed real‑world exploitation yet. However, the remote nature and impact on critical services mean that an attacker could interrupt business processes by exploiting the infinite loop, especially if the services are exposed to external networks.

Generated by OpenCVE AI on August 13, 2026 at 20:54 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the appropriate PTFs (e.g., SJ11101, SJ11097, SJ11102, SJ11098, SJ11103, SJ11099, SJ11104, SJ11100, SJ10899, SJ11022, SJ10848) for your IBM i release and service component.
  • If the system is running an unsupported IBM i release, upgrade to the latest supported and patched version.
  • After patching, restart the affected services or reboot the system and monitor CPU and service responsiveness to confirm the infinite loop no longer occurs.

Generated by OpenCVE AI on August 13, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-835
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T18:51:58.654Z

Reserved: 2026-07-24T20:34:56.935Z

Link: CVE-2026-17229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:19.267

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T23:15:12Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')