Executive brief
IBM i is an enterprise operating system used to run business-critical applications on IBM Power servers. A remote authenticated attacker can exploit an integer underflow vulnerability to corrupt system memory, potentially leading to unauthorized information disclosure, data corruption, or system instability. The vulnerability requires valid user credentials and network access to the affected system.
Technical details
The vulnerability is a heap-based buffer overflow caused by an integer underflow (CWE-122). A remote authenticated attacker can send a specially crafted request to the affected system, triggering the integer underflow condition and corrupting memory. The attack vector is network-based, requires prior authentication (PR:L), and does not require user interaction. Successful exploitation can result in partial loss of confidentiality, integrity, and availability. IBM has released patches (PTFs) for all affected versions: MJ11326 (7.6), MJ11327 (7.5), MJ11328 (7.4), and MJ11329 (7.3).
Affected products
- IBM i 7.6 7.6
- IBM i 7.5 7.5
- IBM i 7.4 7.4
- IBM i 7.3 7.3
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: PTFs released: MJ11326 (7.6), MJ11327 (7.5), MJ11328 (7.4), MJ11329 (7.3)