Executive brief
IBM i is a core business application server platform used by enterprises to run mission-critical workloads. This vulnerability allows an authenticated user to crash their own session through a buffer overflow in the PASE (Portable Application Solutions Environment) subsystem, causing a denial of service. While the impact is limited to individual process termination, it affects multiple versions and requires prompt patching.
Technical details
CVE-2026-19280 is an out-of-bounds write vulnerability (CWE-787) in the PASE process handling code within IBM i. The vulnerability requires local access and authenticated credentials to exploit; a user can trigger the buffer overflow to crash their own process. The attack vector is local with low complexity, and the impact results in availability loss and potential scope change to other components. IBM has released PTF patches for all affected versions (7.3–7.6) through their support portal.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-14: disclosed