Junglewise Threat Intelligence

CVE-2026-17229: IBM i infinite loop denial of service in host servers

CVE-2026-17229 · Severity: high · CVSS 7.5 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system used to run critical business applications and databases. A remote attacker can cause a complete service outage by sending specially crafted network requests that trigger an infinite loop in the host server components, making systems unavailable to legitimate users and disrupting business operations.

Technical details

This vulnerability (CVE-2026-17229) is a classic infinite loop condition (CWE-835) in IBM i host servers that affects versions 7.3 through 7.6. An unauthenticated remote attacker can exploit this flaw by sending malformed network requests to the host server, causing the server process to enter an infinite loop and exhaust system resources. The vulnerability requires no authentication or user interaction and is easily accessible over the network. Exploitation results in denial of service for the affected server component. IBM has released PTFs (SJ11101, SJ11102, SJ11103, SJ11104 for respective versions) to address this issue.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTFs released: SJ11101 (7.6), SJ11102 (7.5), SJ11103 (7.4), SJ11104 (7.3)

References

Related threats