Junglewise Threat Intelligence

CVE-2026-17485: IBM i integer underflow in System Service Tools

CVE-2026-17485 · Severity: high · CVSS 8.2 · Published 2026-08-12

Technologies: IBM i. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system used by organizations to run mission-critical business applications. An integer underflow vulnerability in System Service Tools could allow an unauthenticated remote attacker to crash the system (denial of service) or read sensitive information. This affects IBM i versions 7.3 through 7.6 and patches are now available.

Technical details

The vulnerability is an integer underflow (CWE-125: Out-of-bounds Read) in System Service Tools (SST) component of IBM i. An unauthenticated remote attacker with network access can trigger the underflow condition without prior authentication or user interaction, leading to an out-of-bounds memory read. The attack permits denial of service through system crash and information disclosure of sensitive data in memory. IBM has released PTF patches for all affected versions (7.3, 7.4, 7.5, 7.6).

Affected products

  • IBM IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-12: disclosed
  • 2026-08: patched: PTF patches available for all affected versions

References

Related threats