Executive brief
IBM i is a business-critical server operating system used to run enterprise workloads. A remote attacker can send specially crafted requests to host server components and trigger an infinite loop, causing the affected service to become unresponsive and unavailable to legitimate users. This impacts operational continuity and requires immediate patching.
Technical details
CVE-2026-17004 is a denial of service vulnerability caused by a loop with an unreachable exit condition (infinite loop) in IBM i host servers. A remote, unauthenticated attacker can send malformed requests over the network to trigger this condition, causing the affected host server process to enter an infinite loop and become unresponsive. No code execution or data compromise is possible; the impact is strictly availability. IBM has released PTF patches (SJ11101, SJ11102, SJ11103, SJ11104 for versions 7.6, 7.5, 7.4, 7.3 respectively) to address this and related vulnerabilities in host server components.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed