Executive brief
IBM i is an enterprise server operating system used to run critical business applications. A stack-based buffer overflow vulnerability in the Debug Server component allows authenticated remote attackers to crash the system, resulting in service outages and business disruption.
Technical details
The vulnerability is a stack-based buffer overflow (CWE-121) in IBM i's Debug Server component that can be triggered by a remote authenticated attacker. The attack requires network access and valid credentials; no user interaction is required. An attacker can send a specially crafted request to cause a denial of service by crashing the affected service. IBM has released PTF patches for affected versions (7.3, 7.4, 7.5, 7.6): SJ11308, SJ11307, SJ11306, and SJ11305 respectively.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: PTF SJ11305 (7.6), SJ11306 (7.5), SJ11307 (7.4), SJ11308 (7.3)