Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The IBM i debug server contains a stack‑based buffer overflow (CWE‑121) that is triggered by a local attacker. A malformed debug command causes an overwrite of control data, leading to an immediate crash or unresponsive state of the server process. Because the debug server runs with system privileges, the fault results in a loss of availability for any local users who can invoke it, potentially disrupting critical workloads.

Affected Systems

IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected. All versions shipped by IBM prior to applying the PTFs SJ11308 (7.3), SJ11307 (7.4), SJ11306 (7.5), and SJ11305 (7.6) contain the vulnerable debug server implementation.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. Exploitation requires local authenticated access, limiting the threat to users already logged into the system. The EPSS score is not available and the CVE is not in the CISA KEV list, suggesting that widespread exploitation is currently unlikely. However, because the debug server can be invoked by any local user with the necessary privileges, an attacker can repeatedly cause denial of service within a single session or across multiple sessions, causing significant operational impact.

Generated by OpenCVE AI on September 4, 2026 at 19:05 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11305 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11305 7.5SJ11306 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11306 7.4SJ11307 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11307 7.3SJ11308 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11308 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770‑SS1 update and the related PTF for your release (SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, SJ11308 for 7.3).
  • Disable or restrict the debug server service so it is only available to approved users and for required troubleshooting tasks.
  • Limit local user privileges so that only authorized personnel can access the debug server and monitor system logs for abnormal crashes or repeated debug attempts.

Generated by OpenCVE AI on September 4, 2026 at 19:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Debug Server
First Time appeared Ibm
Ibm i
Weaknesses CWE-121
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:00:33.916Z

Reserved: 2026-07-24T23:19:32.306Z

Link: CVE-2026-17270

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:53.400

Modified: 2026-09-10T21:17:20.523

Link: CVE-2026-17270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow