Impact
IBM i NetServer contains an off‑by‑one bounds‑checking error that can be triggered by a remote attacker who can communicate with the NetServer service. The flaw causes the server to read an out‑of‑bounds memory location, resulting in a crash or restart that makes the entire operating system unavailable to users. The impact is limited to availability, with no direct compromise of confidentiality or integrity. The description and behavior indicate a remote attack via the NetServer interface, a scenario that matches CWE‑125.
Affected Systems
IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected. The vendor has issued PTFs for each release: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6. Systems running any of those releases should apply the specific PTF for their version; unsupported releases should be upgraded to a supported release that contains the fix.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited active exploitation. The likely attack vector is remote via the NetServer interface, requiring network access to the service. The consequence is a loss of availability that could disrupt business operations if the IBM i system is a core platform.
OpenCVE Enrichment