Impact
The IBM i debug server contains a stack‑based buffer overflow (CWE‑121) that is triggered by a local attacker. A malformed debug command causes an overwrite of control data, leading to an immediate crash or unresponsive state of the server process. Because the debug server runs with system privileges, the fault results in a loss of availability for any local users who can invoke it, potentially disrupting critical workloads.
Affected Systems
IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected. All versions shipped by IBM prior to applying the PTFs SJ11308 (7.3), SJ11307 (7.4), SJ11306 (7.5), and SJ11305 (7.6) contain the vulnerable debug server implementation.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Exploitation requires local authenticated access, limiting the threat to users already logged into the system. The EPSS score is not available and the CVE is not in the CISA KEV list, suggesting that widespread exploitation is currently unlikely. However, because the debug server can be invoked by any local user with the necessary privileges, an attacker can repeatedly cause denial of service within a single session or across multiple sessions, causing significant operational impact.
OpenCVE Enrichment