Impact
The vulnerability arises from improper validation of the prefix length in ICMPv6 Router Advertisement packets. An attacker who can send crafted ICMPv6 messages to an IBM i system can trigger a denial of service by forcing the target to crash or reboot. The flaw is a classic buffer processing error captured by CWE‑787, resulting in a loss of availability for affected systems.
Affected Systems
Affected versions include IBM i 7.6, 7.5, 7.4, and 7.3. The build numbers correspond to the IBM product identifiers listed. No specific patch version is noted in the description, but IBM recommends applying the Release5770‑999 update for all affected releases.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely by an attacker with network access capable of injecting malicious ICMPv6 packets. Attackers do not require authentication, making it a high‑impact remote denial‑of‑service vector.
OpenCVE Enrichment