Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (PASE process termination)
Action: Patch
AI Analysis

Impact

An authenticated attacker can leverage a buffer overflow (CWE‑125) in a PASE process on IBM i versions 7.6, 7.5, 7.4, and 7.3 to overwrite memory bounds. The overflow can terminate the process that invoked it, but the impact is confined to that process, not the entire system. The flaw does not provide an avenue for broader system compromise; it simply disrupts availability for the affected account.

Affected Systems

IBM i platforms running any of the major releases 7.6, 7.5, 7.4, or 7.3 are impacted. The vulnerability resides in the PASE process. Each major release has specific PTFs (e.g., MJ11517, MJ11513 for 7.6; MJ11516, MJ11511 for 7.5; MJ11515, MJ11510 for 7.4; MJ11514, MJ11509 for 7.3) that remediate the flaw.

Risk and Exploitability

With a CVSS base score of 3.3, the vulnerability is classified as low severity. The EPSS score is < 1%, indicating an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An authenticated attacker who can launch a PASE process has the ability to trigger a buffer overflow (CWE‑125) that causes termination of the invoked process, resulting in a denial of service that is limited to that account and does not compromise the broader system. Because the attacker must have valid credentials and the impact is confined to a single process, the overall risk remains low.

Generated by OpenCVE AI on September 17, 2026 at 20:01 UTC.

Remediation

Vendor Solution

IBM i Release5770-999  PTF Number(s)PTF Download Link(s)7.6MJ11517 MJ11513 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11517 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11513 7.5MJ11516 MJ11511 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11516 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11511 7.4MJ11515 MJ11510 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11515 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11510 7.3MJ11514 MJ11509 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11514 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11509 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-999 patch set that includes the relevant PTFs for your system release (e.g., MJ11517 and MJ11513 for 7.6, MJ11516 and MJ11511 for 7.5, MJ11515 and MJ11510 for 7.4, MJ11514 and MJ11509 for 7.3).
  • Ensure that only authorized users have the permissions to invoke PASE processes; restrict privileges.
  • Monitor the system for abrupt process terminations or other anomalous events that could indicate exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Title IBM i is Affected By Multiple Vulnerabilities in PASE [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:47.444Z

Reserved: 2026-08-06T12:22:07.522Z

Link: CVE-2026-19086

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:52.973Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:04.350

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-19086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses