Executive brief
IBM i is an enterprise operating system used to run business-critical applications and services. A buffer overflow vulnerability in its PASE (Portable Application Solutions Environment) component allows authenticated users to crash their own processes, causing temporary service disruptions. While the impact is limited to individual process termination by authenticated users, this could be leveraged to disrupt operations or as part of a larger attack.
Technical details
This is an out-of-bounds read vulnerability (CWE-125) in the PASE subsystem of IBM i. The vulnerability requires local authentication and user interaction is not needed. An authenticated attacker can trigger the buffer overflow to read memory beyond intended boundaries, leading to denial of service through process termination. The vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6. IBM has released PTF patches for all affected versions, and no exploit in the wild has been reported.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-14: disclosed