Executive brief
IBM i is an operating system used by many enterprises for critical business applications and data processing. A remote authenticated attacker can exploit a NULL pointer dereference vulnerability in the Debug Server component to crash the system and cause a denial of service, disrupting business operations until the system is restarted.
Technical details
A NULL pointer dereference vulnerability (CWE-476) exists in IBM i's Debug Server component affecting versions 7.3 through 7.6. The vulnerability requires authentication and network access, meaning an attacker must have valid credentials to exploit it. By sending a specially crafted network request, an authenticated attacker can trigger a NULL pointer dereference that causes the Debug Server to crash, resulting in denial of service. IBM has released PTF patches for all affected versions (SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, and SJ11308 for 7.3).
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-08-31: patched: PTF patches available: SJ11305 (7.6), SJ11306 (7.5), SJ11307 (7.4), SJ11308 (7.3)