Junglewise Threat Intelligence

CVE-2026-17029: IBM i out-of-bounds write in Java Secure Sockets Extension

CVE-2026-17029 · Severity: high · CVSS 8.8 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system that runs business-critical applications and workloads. A vulnerability in its Java Secure Sockets Extension (JSSE) component allows a local attacker with basic privileges to execute arbitrary code with elevated access, potentially compromising the entire system. This could lead to data theft, system compromise, or operational disruption.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in IBM i 7.3–7.6 within the Java Secure Sockets Extension (JSSE), a core cryptographic and TLS component. The vulnerability requires local access and low-level privileges to trigger. An attacker can craft input that overflows a buffer during TLS session establishment, allowing them to write to memory outside the intended bounds and execute arbitrary code with the privileges of the Java Virtual Machine. IBM has released platform-specific PTFs (program temporary fixes) for all affected versions (7.3–7.6).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-12: disclosed: IBM security bulletin published
  • 2026-08-12: patched: PTFs released for IBM i 7.3, 7.4, 7.5, and 7.6

References

Related threats