Executive brief
IBM i is an enterprise-grade operating system used by organizations to run mission-critical business applications. A heap buffer overflow vulnerability in IBM i's host servers allows remote attackers to cause service outages by sending specially crafted requests, disrupting business operations and availability without requiring authentication.
Technical details
This vulnerability (CVE-2026-16982) is a heap-based buffer overflow (CWE-787) in IBM i host servers caused by improper validation of client-supplied data. A remote, unauthenticated attacker can send malformed requests to affected host servers, triggering an out-of-bounds write condition that crashes the server and causes denial of service. The vulnerability is network-accessible with low attack complexity, requiring no authentication or user interaction. Patches are available as PTFs (SJ11101, SJ11102, SJ11103, SJ11104 for versions 7.6, 7.5, 7.4, and 7.3 respectively).
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed
- 2026-08-13: patched: PTFs available: 7.6 (SJ11101, SJ11097), 7.5 (SJ11102, SJ11098), 7.4 (SJ11103, SJ11099), 7.3 (SJ11104, SJ11100)