Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Published: 2026-08-13
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write within the NetServer component of IBM i, discovered in versions 7.3 through 7.6. A malicious remote actor could trigger the flaw and cause a denial of service by corrupting memory, leading to crashes or unresponsive services. The flaw is classified as CWE‑787, indicating improper bounds checking during memory operations. The high CVSS score of 8.6 reflects the significant impact on availability.

Affected Systems

Affected are IBM i releases 7.3, 7.4, 7.5, and 7.6. For each release, IBM has issued a PTF: 7.6MJ10939 for 7.6, 7.5MJ10938 for 7.5, 7.4MJ10937 for 7.4, and 7.3MJ10936 for 7.3. These patches address the NetServer out‑of‑bounds write and restore normal function.

Risk and Exploitability

The stated CVSS of 8.6 signals a high‑severity risk. EPSS is not available, so the current exploit probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Attackers would need to reach the NetServer port from the network and trigger the memory overwrite; no local privilege escalation or authentication is required, making it feasible for a remote attacker. The effect is to disrupt service availability on the affected IBM i system.

Generated by OpenCVE AI on August 13, 2026 at 23:18 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and install the IBM PTF for your IBM i version (7.6MJ10939, 7.5MJ10938, 7.4MJ10937, or 7.3MJ10936).
  • Reboot the IBM i system to ensure all affected services run under the patched code.
  • If your system is running an unsupported IBM i release, upgrade to a supported version that includes the fix, or discontinue usage of NetServer until a patch is available.

Generated by OpenCVE AI on August 13, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:40:54.777Z

Reserved: 2026-07-26T18:55:48.680Z

Link: CVE-2026-17502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:43.677

Modified: 2026-08-13T21:17:43.677

Link: CVE-2026-17502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T23:30:03Z

Weaknesses