Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A stack-based buffer overflow in the debug server of IBM i allows a remote authenticated attacker to cause a denial of service. An attacker who can authenticate to the debug service can trigger a crash that interrupts system availability. The problem is not an elevation of privilege; it is purely an availability issue, reflected in a CVSS score of 4.3.

Affected Systems

IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The fix is distributed through PTFs SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, and SJ11308 for 7.3, and the release 5770‑SS1.

Risk and Exploitability

The CVSS score of 4.3 suggests low to moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation is not currently documented. The attack requires the attacker to have valid credentials to the debug server, so the risk is limited to environments that expose that service and have in‑place authentication mechanisms. If those conditions are met, the attacker can interrupt operations by inducing a stack overflow that terminates the debug server process.

Generated by OpenCVE AI on September 4, 2026 at 17:59 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11305 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11305 7.5SJ11306 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11306 7.4SJ11307 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11307 7.3SJ11308 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11308 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the PTF for your version (SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, or SJ11308 for 7.3).
  • Upgrade to IBM i Release5770‑SS1 or a later supported release that contains the fix.
  • Restrict or disable the debug server service to only trusted administrators, reducing the attack surface.

Generated by OpenCVE AI on September 4, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Debug Server
First Time appeared Ibm
Ibm i
Weaknesses CWE-121
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:31:32.959Z

Reserved: 2026-07-24T22:25:45.144Z

Link: CVE-2026-17259

cve-icon Vulnrichment

Updated: 2026-09-04T17:31:29.760Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:53.267

Modified: 2026-09-08T17:12:16.610

Link: CVE-2026-17259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:00:12Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow