Executive brief
IBM i is an enterprise operating system used to run mission-critical business applications. The Debug Server component contains a memory leak that allows authenticated remote attackers to exhaust system memory and cause service outages, impacting availability of dependent business operations.
Technical details
IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a memory leak vulnerability (CWE-401: Missing Release of Memory after Effective Lifetime) in the Debug Server component. An authenticated attacker with remote network access can trigger the memory leak condition, causing the affected system to consume memory until resources are exhausted, resulting in denial of service. Authentication is required to exploit this vulnerability. IBM has released PTFs (Program Temporary Fixes) for all affected versions: SJ11305 (7.6), SJ11306 (7.5), SJ11307 (7.4), and SJ11308 (7.3).
Affected products
- IBM i 7.6 7.6
- IBM i 7.5 7.5
- IBM i 7.4 7.4
- IBM i 7.3 7.3
Timeline
- 2026-09-04: disclosed