Junglewise Threat Intelligence

CVE-2026-17255: IBM i denial of service in ICMPv6 Router Advertisement handling

CVE-2026-17255 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Executive brief

IBM i is an enterprise operating system used to run mission-critical business applications and services. A remote attacker can crash or degrade performance of affected systems by sending specially crafted ICMPv6 Router Advertisement packets with invalid prefix lengths. This vulnerability could disrupt business operations and require system restarts, but does not compromise data confidentiality or integrity.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) caused by improper validation of the prefix length field in ICMPv6 Router Advertisements. An unauthenticated remote attacker on an adjacent network segment can send a malicious ICMPv6 packet without user interaction to trigger the flaw. The attack results in a denial of service condition affecting system availability. IBM has released Platform Test Fixes (PTFs) for all affected versions: MJ11322 (7.6), MJ11323 (7.5), MJ11324 (7.4), and MJ11325 (7.3).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed

References

Related threats