Executive brief
IBM i is an enterprise operating system used for running critical business applications. A stack-based buffer overflow vulnerability in the Simple Mail Transfer Protocol (SMTP) component allows remote attackers to crash the system and cause denial of service without authentication. This could disrupt email functionality and potentially the broader system that relies on it.
Technical details
A stack-based buffer overflow (CWE-787: Out-of-bounds Write) exists in the SMTP component of IBM i versions 7.3, 7.4, 7.5, and 7.6. The vulnerability is remotely exploitable over the network with no authentication or user interaction required. An attacker can send a specially crafted SMTP message to trigger the overflow, causing a denial of service by crashing the affected process or system. IBM has released PTF patches for all supported versions (7.3 through 7.6).
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed: IBM security bulletin published
- 2026-08-12: patched: PTF patches available for versions 7.3–7.6