Executive brief
IBM i is an enterprise operating system for mid-range business servers used to run mission-critical applications and databases. A buffer overflow vulnerability in host servers could allow authenticated remote attackers to execute arbitrary code on affected systems, potentially compromising the entire server and any data or applications running on it.
Technical details
CVE-2026-17223 is a buffer overflow vulnerability (CWE-787: Out-of-bounds Write) in IBM i host servers that allows a remote authenticated attacker to execute arbitrary code. The vulnerability stems from improperly validated input handling in host server components, requiring authentication but no user interaction. An attacker with valid credentials can send specially crafted requests to trigger the buffer overflow and gain code execution with system privileges. IBM has released PTFs for all affected versions (7.3, 7.4, 7.5, 7.6), including SJ11104/SJ11100, SJ11103/SJ11099, SJ11102/SJ11098, and SJ11101/SJ11097 respectively.
Affected products
- IBM i 7.6 7.6
- IBM i 7.5 7.5
- IBM i 7.4 7.4
- IBM i 7.3 7.3
Timeline
- 2026-08-13: disclosed