Executive brief
IBM i is an enterprise operating system used to run business-critical applications and data management systems. A remote attacker can trigger a denial of service by exploiting an off-by-one error in the NetServer bounds checking logic, disrupting access to services and potentially impacting business operations.
Technical details
The vulnerability is an off-by-one error in bounds checking within IBM i NetServer (CWE-125: Out-of-bounds Read). A remote, unauthenticated attacker can send a crafted network request to trigger an out-of-bounds read condition, causing the NetServer service to crash or become unresponsive. The attack requires network connectivity to the affected system and no special privileges or user interaction. The impact is limited to availability; no confidentiality or integrity compromise is possible. IBM has released PTF MJ10939 for IBM i 7.6 and corresponding patches for earlier versions.
Affected products
- IBM i 7.6 7.6
- IBM i 7.5 7.5
- IBM i 7.4 7.4
- IBM i 7.3 7.3
Timeline
- 2026-08-13: disclosed