Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Null Pointer Dereference
Action: Apply Patch
AI Analysis

Impact

A remote authenticated attacker can exploit a null pointer dereference in the IBM i debug server to terminate the service, resulting in a denial of service for applications that rely on the debug server. The flaw occurs when the debug server processes a specially crafted request that forces a null reference, causing an internal failure. The impact is limited to the availability of the debug server and any dependent services, but it does not provide direct information disclosure or privilege escalation. The underlying weakness is a classic Null Pointer Dereference (CWE‑476).

Affected Systems

IBM i operating systems 7.6, 7.5, 7.4 and 7.3 are impacted. The affected product is IBM i, and the version identifiers 7.6, 7.5, 7.4 and 7.3 are explicitly named in the advisory.

Risk and Exploitability

The CVSS v3.1 score of 6.5 indicates a moderate severity. Because the exploit requires authentication on the debug server, the attack vector is remote but not unrestricted; the attacker must have legitimate credentials. EPSS is not provided, but the lack of a KEV listing suggests no known widespread exploitation yet. Nevertheless, the impact on availability can disrupt critical business processes, especially in environments that rely heavily on the debug service. The risk is therefore significant for organizations that allow remote debugging access or operate unsupported versions of IBM i.

Generated by OpenCVE AI on September 4, 2026 at 18:00 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11305 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11305 7.5SJ11306 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11306 7.4SJ11307 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11307 7.3SJ11308 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11308 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the released IBM i PTFs: SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, and SJ11308 for 7.3.
  • Ensure the system is running a supported and updated IBM i release; older, unsupported versions should be upgraded or retired.
  • If immediate patch deployment is not possible, disable or restrict access to the debug server and remove remote debugging capabilities while a fix is applied.

Generated by OpenCVE AI on September 4, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
Title IBM i is Affected By Multiple Vulnerabilities in Debug Server
First Time appeared Ibm
Ibm i
Weaknesses CWE-476
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:00:34.088Z

Reserved: 2026-07-24T23:28:44.572Z

Link: CVE-2026-17273

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:53.570

Modified: 2026-09-10T21:17:21.033

Link: CVE-2026-17273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:00:12Z

Weaknesses