Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
Published: 2026-08-12
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i releases 7.6, 7.5, 7.4, and 7.3 contain an integer underflow that can be triggered by a remote attacker. The flaw can cause a denial of service and allow the attacker to read sensitive data. This flaw involves CWE‑125 and CWE‑191 and compromises both availability and confidentiality.

Affected Systems

IBM i releases 7.6, 7.5, 7.4, and 7.3 are vulnerable, as identified by the IBM i PTFs MJ10909, MJ10863, MJ10862, and MJ10861, respectively. All affected installations should apply the corresponding PTF or upgrade to a supported, fixed release.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. EPSS score is less than 1%, which suggests a very low but non‑zero likelihood of exploitation, and the issue is not currently listed in the CISA KEV catalog. However, the flaw can be remotely exploited to disrupt services and potentially expose confidential data, involving both integer underflow (CWE‑125) and signed integer arithmetic failure (CWE‑191). Immediate patching is recommended to mitigate exploit risk.

Generated by OpenCVE AI on August 17, 2026 at 20:44 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10909 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10909 7.5MJ10863 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10863 7.4MJ10862 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10862 7.3MJ10861 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10861 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs for the corresponding release (e.g., MJ10909 for 7.6, MJ10863 for 7.5, MJ10862 for 7.4, MJ10861 for 7.3).
  • If running an unsupported IBM i release, upgrade to a supported and fixed version as recommended by IBM.
  • Monitor system resources for signs of exhaustion and configure alerts to detect unexpected service interruptions.

Generated by OpenCVE AI on August 17, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-191
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 14 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
Title IBM i is Affected By Denial of Service Vulnerability []
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T22:21:12.830Z

Reserved: 2026-07-25T23:31:09.079Z

Link: CVE-2026-17485

cve-icon Vulnrichment

Updated: 2026-08-14T22:21:08.962Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T22:17:14.433

Modified: 2026-08-17T15:47:26.537

Link: CVE-2026-17485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T20:45:17Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-191

    Integer Underflow (Wrap or Wraparound)