Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability arises from improper validation of the prefix length in ICMPv6 Router Advertisement packets. An attacker who can send crafted ICMPv6 messages to an IBM i system can trigger a denial of service by forcing the target to crash or reboot. The flaw is a classic buffer processing error captured by CWE‑787, resulting in a loss of availability for affected systems.

Affected Systems

Affected versions include IBM i 7.6, 7.5, 7.4, and 7.3. The build numbers correspond to the IBM product identifiers listed. No specific patch version is noted in the description, but IBM recommends applying the Release5770‑999 update for all affected releases.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely by an attacker with network access capable of injecting malicious ICMPv6 packets. Attackers do not require authentication, making it a high‑impact remote denial‑of‑service vector.

Generated by OpenCVE AI on September 4, 2026 at 17:59 UTC.

Remediation

Vendor Solution

IBM i Release5770-999  PTF Number(s)PTF Download Link(s)7.6MJ11322 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11322 7.5MJ11323 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11323 7.4MJ11324 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11324 7.3MJ11325 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11325 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770‑999 update and install the relevant PTFs: MJ11322 for 7.6, MJ11323 for 7.5, MJ11324 for 7.4, or MJ11325 for 7.3.
  • If the system cannot be updated immediately, block or filter ICMPv6 Router Advertisement traffic using firewall or router configuration to prevent delivery of malformed packets.
  • Continuously monitor system logs for abnormal ICMPv6 traffic and denial‑of‑service symptoms, and review network traffic for injected Router Advertisement messages.

Generated by OpenCVE AI on September 4, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
Title IBM i is Affected By Denial of Service Vulnerability []
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T15:06:37.340Z

Reserved: 2026-07-24T22:14:14.142Z

Link: CVE-2026-17255

cve-icon Vulnrichment

Updated: 2026-09-09T18:27:29.356Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:53.140

Modified: 2026-09-10T16:17:08.337

Link: CVE-2026-17255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:45:03Z

Weaknesses