Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Published: 2026-09-14
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via buffer overflow in a PASE process
Action: Patch
AI Analysis

Impact

The vulnerability is a buffer overflow that occurs when an authenticated attacker opens a PASE process on IBM i 7.6, 7.5, 7.4, or 7.3. The overflow corrupts the stack, causing the offending process to terminate. The exploit’s impact is confined to the attacker‑controlled process, leading only to a local denial of service.

Affected Systems

IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected by this flaw. Each release has dedicated patches: for 7.6 – MJ11517 and MJ11513; for 7.5 – MJ11516 and MJ11511; for 7.4 – MJ11515 and MJ11510; for 7.3 – MJ11514 and MJ11509. Unsupported or older releases should be upgraded to the latest supported IBM i release that contains the fix.

Risk and Exploitability

The CVSS score of 5.2 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is launching a malicious PASE process as an authenticated user; this inference comes from the requirement for authentication and the description of a PASE process. Exploitation causes only the attacker’s own process to fail, without affecting other processes or the overall system.

Generated by OpenCVE AI on September 20, 2026 at 18:40 UTC.

Remediation

Vendor Solution

IBM i Release5770-999  PTF Number(s)PTF Download Link(s)7.6MJ11517 MJ11513 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11517 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11513 7.5MJ11516 MJ11511 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11516 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11511 7.4MJ11515 MJ11510 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11515 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11510 7.3MJ11514 MJ11509 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11514 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11509 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply IBM i Release 5770-999; if on an older release, install the corresponding PTFs: for 7.6 – MJ11517 and MJ11513; for 7.5 – MJ11516 and MJ11511; for 7.4 – MJ11515 and MJ11510; for 7.3 – MJ11514 and MJ11509 – using the PTF downloads provided by IBM.
  • If a patch cannot be applied immediately, restart the PASE service or reboot the system so that the patched binaries are loaded.
  • If the system runs an unsupported IBM i release, upgrade to the latest supported release that includes the fix.

Generated by OpenCVE AI on September 20, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Title IBM i is Affected By Multiple Vulnerabilities in PASE [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T18:04:12.744Z

Reserved: 2026-08-07T15:31:49.343Z

Link: CVE-2026-19280

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:40.355Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:04.627

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-19280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses