Junglewise Threat Intelligence

CVE-2026-17469: IBM i off-by-one write in Line Printer Daemon queue parser

CVE-2026-17469 · Severity: medium · CVSS 5.3 · Published 2026-09-04

Executive brief

IBM i is an enterprise operating system that manages critical business applications and data. This vulnerability allows authenticated users with local access to cause the system to crash by exploiting a buffer overflow flaw in the Line Printer Daemon (LPD) queue name parser, resulting in service outages and business disruption.

Technical details

An off-by-one write vulnerability (CWE-787: Out-of-bounds Write) exists in the Line Printer Daemon (LPD) queue name parser in IBM i. The vulnerability requires local authentication and can be triggered by an attacker with authorized system access. By providing a specially crafted queue name, an attacker can write one byte past the bounds of a buffer, corrupting memory and causing a denial of service. Patches are available through PTF releases for versions 7.6, 7.5, 7.4, and 7.3.

Affected products

  • IBM IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed: IBM security bulletin published
  • 2026-09-04: patched: PTF releases available: SJ11303 (7.3), SJ11302 (7.4), SJ11301 (7.5), SJ11300 (7.6)

References

Related threats