Executive brief
IBM i systems are vulnerable to a denial-of-service attack through its Integrated Language Environment (ILE) compiler. An authorized user could crash the system or disrupt operations by attempting to compile specially crafted source code. This could lead to unplanned downtime and impact business-critical applications running on the platform.
Technical details
A vulnerability exists in the IBM i Integrated Language Environment (ILE) compiler (CWE-674) due to uncontrolled recursion. An authenticated attacker with network access can trigger this condition by submitting specially crafted source code for compilation that contains a specific combination of statements. Successful exploitation leads to a denial-of-service (DoS) condition. IBM has released Program Temporary Fixes (PTFs) MJ09365, MJ09335, MJ09334, and MJ09332 to address this issue across supported versions 7.3 through 7.6.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-05-13: disclosed: Initial publication by IBM
- 2026-05-13: patched: PTFs released by IBM
- 2026-05-27: advisory: NVD publication date