Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stack-based buffer overflow that enables a remote attacker, through Simple Mail Transfer Protocol traffic, to crash an IBM i system and deny service to legitimate users. The flaw arises when the SMTP component fails to properly bound input data, allowing the attacker to overflow the stack and cause an abrupt termination of the SMTP service, which in turn can cascade to overall system instability. The lack of proper input validation is the root cause of the exploitability, as identified by the associated CWE-787.

Affected Systems

IBM i releases 7.3, 7.4, 7.5, and 7.6 are impacted. The specific patch levels are available through IBM PTFs SJ11061 and SJ11131 for 7.6, SJ11074 and SJ11129 for 7.5, SJ11083 and SJ11127 for 7.4, and SJ11084 and SJ11123 for 7.3. Users running unsupported versions should upgrade to a supported release that incorporates these fixes.

Risk and Exploitability

The CVSS score of 7.5 places this flaw in the high severity range, and while an EPSS score is not available, there is no evidence of widespread exploitation and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be Remote Network, specifically via SMTP traffic, given the description of the overflow occurring during mail transfer processing. An attacker with network access to the server could trigger a DoS by sending crafted SMTP commands that trigger the buffer overflow, leading to a crash of the SMTP service and potentially broader system unavailability.

Generated by OpenCVE AI on August 13, 2026 at 22:40 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-TC1 PTF Number(s)PTF Download Link(s)7.6SJ11061 SJ11131 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11061 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11131 7.5SJ11074 SJ11129 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11074 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11129 7.4SJ11083 SJ11127 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11083 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11127 7.3SJ11084 SJ11123 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11084 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11123  https://www.ibm.com/mysupport/s/fix-information IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the applicable IBM i PTFs—SJ11061 and SJ11131 for 7.6, SJ11074 and SJ11129 for 7.5, SJ11083 and SJ11127 for 7.4, or SJ11084 and SJ11123 for 7.3—to patch the stack‑based buffer overflow.
  • Ensure the system is running a supported IBM i release that includes the fix; if the current release is unsupported, plan an upgrade to a supported version immediately.
  • If the system must continue to accept SMTP connections before the patches are applied, restrict inbound SMTP traffic to known, authorized hosts via firewall or access control rules to reduce exposure.

Generated by OpenCVE AI on August 13, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:41:56.635Z

Reserved: 2026-07-28T15:12:51.754Z

Link: CVE-2026-18077

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:44.230

Modified: 2026-08-13T21:17:44.230

Link: CVE-2026-18077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T01:15:16Z

Weaknesses