Junglewise Threat Intelligence

CVE-2026-17270: IBM i stack-based buffer overflow in Debug Server

CVE-2026-17270 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Executive brief

IBM i is a business-critical operating system used to run mission-critical enterprise applications and databases. A stack-based buffer overflow vulnerability in the Debug Server component allows local attackers to cause the system to crash or become unavailable, disrupting operations that depend on this platform.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in IBM i's Debug Server component, allowing a local attacker with user-level privileges to trigger a denial of service condition. The vulnerability is reachable via local attack vector with low attack complexity and no user interaction required. Exploitation causes the affected process to crash, resulting in service unavailability. IBM has released cumulative security patches (PTF SJ11305/SJ11306/SJ11307/SJ11308) for IBM i 7.6, 7.5, 7.4, and 7.3 respectively.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: PTF SJ11305 (7.6), SJ11306 (7.5), SJ11307 (7.4), SJ11308 (7.3)

References

Related threats