Executive brief
IBM i is an integrated enterprise operating system running on IBM Power systems that handles critical business applications, backup, and restore operations. An authenticated attacker can trigger a denial-of-service condition by exploiting an integer overflow vulnerability in the Save Restore component, causing the system to become unavailable and disrupting business operations and data protection workflows.
Technical details
An integer overflow vulnerability (CWE-190) exists in the Save Restore component of IBM i versions 7.3 through 7.6. The vulnerability requires remote network access and valid user authentication; an unauthenticated attacker cannot exploit it. When triggered, the overflow causes a denial-of-service condition that makes the affected system unavailable. IBM has released patches (PTF SJ11369 for 7.6, SJ11368 for 7.5, SJ11367 for 7.4, and SJ11366 for 7.3) to remediate the issue. No workarounds are available.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed: CVE published on NVD
- 2026-09-01: patched: IBM released patches for all affected versions