Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via buffer overflow in a PASE process
Action: Patch
AI Analysis

Impact

A buffer overflow occurs in a PASE process on IBM i versions 7.6, 7.5, 7.4, and 7.3. The flaw, identified as CWE-125, allows an attacker to overwrite memory bounds and terminate the process that invoked the overflow. The level, affecting only the user’s own process rather than the entire system.

Affected Systems

IBM i platforms running any of the major releases 7.6, 7.5, 7.4, or 7.3 are impacted. The vulnerability resides in the PASE environment and is documented across all these releases. Each major release has specific PTFs (e.g., MJ11517, MJ11513 for 7.6; MJ11516, MJ11511 for 7.5; MJ11515, MJ11510 for 7.4; MJ11514, MJ11509 for 7.3) that remediate the flaw.

Risk and Exploitability

With a CVSS base score of 3.3, the vulnerability is considered low severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, indicating no known public exploitation. The attack requires the attacker to be authenticated to the IBM i system and to have the ability to launch a PASE process; this is inferred from the description. Once authenticated, the attacker can trigger the overflow to kill only their own process, potentially disrupting services for that account but not granting broader system compromise. The overall risk is moderate, driven primarily by the need for authenticated access and the impact on availability for the affected user.

Generated by OpenCVE AI on September 15, 2026 at 10:25 UTC.

Remediation

Vendor Solution

IBM i Release5770-999  PTF Number(s)PTF Download Link(s)7.6MJ11517 MJ11513 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11517 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11513 7.5MJ11516 MJ11511 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11516 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11511 7.4MJ11515 MJ11510 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11515 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11510 7.3MJ11514 MJ11509 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11514 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11509 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-999 patch set that includes PTFs MJ11517, MJ11513, MJ11516, MJ11511, MJ11515, MJ11510, MJ11514, and MJ11509, matching your platform version.
  • Ensure only authorized users can invoke PASE processes; restrict privileges for accounts that may run arbitrary PASE programs.
  • Monitor the system for abrupt process terminations and investigate any anomalous events that could indicate exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Title IBM i is Affected By Multiple Vulnerabilities in PASE [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T21:03:44.860Z

Reserved: 2026-08-06T12:22:07.522Z

Link: CVE-2026-19086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:04.350

Modified: 2026-09-14T21:17:04.350

Link: CVE-2026-19086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:30:12Z

Weaknesses