Impact
IBM i versions 7.3 through 7.6 have a flaw in the Line Printer Daemon (LPD) queue name parser that can be triggered by an off‑by‑one write. A local authenticated attacker can exploit this to cause a denial of service, halting printer service functionality.
Affected Systems
The affected products are IBM i running releases 7.3, 7.4, 7.5, or 7.6. For each release the recommended fix is a specific IBM PTF: SJ11300 for 7.6, SJ11301 for 7.5, SJ11302 for 7.4, and SJ11303 for 7.3.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity; the EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local authentication to the IBM i system, meaning that users with sufficient privileges can trigger the denial of service by sending a crafted queue name to the LPD service. No remote exploitation is described, so the threat is confined to environments where local authenticated users have service‑management credentials.
OpenCVE Enrichment