Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
Published: 2026-08-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote attacker can trigger a buffer overflow in IBM i versions 7.6, 7.5, 7.4, and 7.3, leading to a denial of service of the HTTP server. The vulnerability is a classic out‑of‑bounds write (CWE‑787) that corrupts memory and causes the service to crash. The impact is the loss of availability of the HTTP service for legitimate users, potentially affecting critical business functions that rely on IBM i web services.

Affected Systems

The affected systems are IBM i releases 7.6, 7.5, 7.4, and 7.3. IBM provides specific PTFs for each release: SJ10845 for 7.6, SJ10844 for 7.5, SJ10843 for 7.4, and SJ10842 for 7.3. Users on these releases should update to the latest fix package or, if running a non‑supported version, upgrade to a supported, patched release per IBM recommendations.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability. The EPSS score is not available, so the current quantified likelihood of exploitation is unknown, but the lack of a KEV listing suggests no confirmed exploits are publicly known yet. The likely attack vector is remote, via the HTTP server, with no authentication required to send the malformed request that triggers the buffer overflow. Given the high CVSS and the nature of the flaw, the risk of an active exploitation is significant until the patch is applied.

Generated by OpenCVE AI on August 13, 2026 at 21:47 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-DG1 PTF Number(s)PTF Download Link(s)7.6SJ10845 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10845 7.5SJ10844 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10844 7.4SJ10843 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10843 7.3SJ10842 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10842 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and apply the PTF specific to your IBM i release from the IBM support links, ensuring the HTTP server binaries are updated.
  • Restart the HTTP server to load the patched binaries and verify the service is stable.
  • If the system runs an unsupported version, upgrade to the latest supported, patched IBM i release as recommended by IBM.

Generated by OpenCVE AI on August 13, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
Title IBM i is Affected By a Denial of Service in HTTP Server []
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T18:07:47.465Z

Reserved: 2026-07-24T23:26:46.428Z

Link: CVE-2026-17272

cve-icon Vulnrichment

Updated: 2026-08-14T17:41:27.979Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T21:17:42.687

Modified: 2026-08-19T16:38:40.920

Link: CVE-2026-17272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T23:45:16Z

Weaknesses