Executive brief
IBM i is an enterprise operating system used to run mission-critical business applications and services. A remote attacker can crash or degrade performance of affected systems by sending specially crafted ICMPv6 Router Advertisement packets with invalid prefix lengths. This vulnerability could disrupt business operations and require system restarts, but does not compromise data confidentiality or integrity.
Technical details
The vulnerability is an out-of-bounds write (CWE-787) caused by improper validation of the prefix length field in ICMPv6 Router Advertisements. An unauthenticated remote attacker on an adjacent network segment can send a malicious ICMPv6 packet without user interaction to trigger the flaw. The attack results in a denial of service condition affecting system availability. IBM has released Platform Test Fixes (PTFs) for all affected versions: MJ11322 (7.6), MJ11323 (7.5), MJ11324 (7.4), and MJ11325 (7.3).
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed