Executive brief
IBM i is a critical enterprise operating system used by many Fortune 500 companies to run mission-critical business applications. A buffer overflow vulnerability in its Network File System (NFS) component allows remote attackers to crash the system and corrupt data without requiring authentication or user interaction. This can disrupt business operations and compromise the integrity of stored data.
Technical details
A buffer overflow vulnerability (CWE-787: Out-of-bounds Write) exists in the Network File System (NFS) implementation within IBM i versions 7.3 through 7.6. The vulnerability is remotely exploitable over the network without authentication, precondition, or user interaction (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U). An attacker can send a specially crafted NFS request to trigger the out-of-bounds write, leading to denial of service and data integrity compromise. IBM has released platform-specific patches (PTFs SJ11317 through SJ11320) for all affected versions.
Affected products
- IBM i 7.6 7.6
- IBM i 7.5 7.5
- IBM i 7.4 7.4
- IBM i 7.3 7.3
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: PTF SJ11320 (7.6), SJ11319 (7.5), SJ11318 (7.4), SJ11317 (7.3)