Junglewise Threat Intelligence

CVE-2026-17470: IBM i buffer overflow in Line Printer Daemon

CVE-2026-17470 · Severity: medium · CVSS 5.3 · Published 2026-09-04

Executive brief

IBM i is an enterprise operating system that manages critical business applications and data on Power Systems servers. A buffer overflow vulnerability in the Line Printer Daemon (LPD) component allows a remote attacker without authentication to cause service unavailability by crashing the printing subsystem. This could disrupt operations for organizations that rely on network printing infrastructure.

Technical details

The vulnerability is a classic out-of-bounds write (CWE-787) in the Line Printer Daemon handling code. A remote attacker can send a specially crafted network request to the LPD service (accessible over the network without requiring authentication) that triggers a buffer overflow, leading to denial of service. The vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6. Patches are available for all affected versions via Program Temporary Fixes (PTFs): SJ11303 (7.3), SJ11302 (7.4), SJ11301 (7.5), and SJ11300 (7.6).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-01: disclosed
  • 2026-09-04: advisory

References

Related threats