Sceawere

Vulnerability Detail

CVE-2026-16931UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i TCP Options Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1h ago
Vendor
IBM
Product
i
Attack Type
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-12T18:17:25.010Z",
  "pubdate": "2026-08-12T18:17:25.010Z",
  "executiveSummary": "A denial of service vulnerability exists within IBM i versions 7.6, 7.5, 7.4, and 7.3 due to improper handling of zero-length TCP options.\nThis vulnerability allows a remote attacker to compromise system availability by causing a denial of service condition on affected targets.\nThe flaw stems from deficient input validation and parsing logic within the networking stack when processing maliciously crafted Transmission Control Protocol packets containing zero-length option fields.\nSuccessful exploitation of this issue requires network connectivity to the targeted IBM i system, allowing remote threat actors to disrupt critical services without requiring authentication or elevated privileges.\nThe resulting denial of service impairs system responsiveness and operational continuity, posing significant risk to enterprise environments relying on continuous availability of IBM i infrastructure.\nMitigation requires applying official patches or vendor-supplied fixes designed to correct the parsing anomalies associated with zero-length TCP options.",
  "technicalDetails": "The vulnerability resides within the TCP/IP stack implementation of IBM i, specifically inside the packet parsing and option-handling routines responsible for processing incoming TCP segments.\nThe root cause is improper handling and validation of zero-length TCP options embedded within the TCP header structure.\nWhen a remote attacker transmits specially crafted TCP packets containing zero-length option fields, the affected networking component fails to correctly compute option boundaries or advance parsing pointers appropriately.\nThis parsing failure leads to exceptions, infinite loops, memory corruption, or resource exhaustion within the kernel or networking subsystem, directly precipitating a denial of service.\nThe attack vector is network-based, allowing unauthenticated remote attackers to interact directly with the TCP/IP stack of the target operating system.\nNo prior authentication or privileged access is required to transmit the offending TCP segments, lowering the barrier to exploitation.\nAffected products and versions include IBM i 7.6, 7.5, 7.4, and 7.3.\nThe step-by-step attack flow involves the attacker crafting a malicious TCP packet with an invalid or zero-length option field, transmitting the packet across the network interface to the vulnerable IBM i host, and triggering the flawed option-processing routine upon receipt by the network stack.\nThe post-exploitation impact is strictly focused on availability, manifesting as a system hang, kernel panic, or complete network stack crash, which effectively denies legitimate users access to services hosted on the IBM i platform."
}
CVE-2026-16931: IBM i TCP Options Denial of Service (HIGH Severity, CVSS: 7.5) - Sceawere