Sceawere
Vulnerability Detail
CVE-2026-17004UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Denial of Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-13T20:17:17.660Z",
"pubdate": "2026-08-13T20:17:17.660Z",
"executiveSummary": "A denial of service vulnerability exists within IBM i versions 7.3, 7.4, 7.5, and 7.6 that can be leveraged by a remote attacker.\nThe core vulnerability type involves an infinite loop condition, which leads directly to a denial of service impact by exhausting system resources and rendering the affected service or system unresponsive.\nThe risk implications are severe for availability, as successful exploitation disrupts normal operations and prevents legitimate users from accessing critical system services.\nThe attacker capabilities required involve the ability to interact remotely with the vulnerable product to trigger the flawed execution path.\nExploitation requirements rely on reaching the vulnerable component over the network to initiate the sequence that results in the infinite loop.\nNo specific authentication or heightened privileges are explicitly detailed beyond remote network accessibility to the affected system functions.",
"technicalDetails": "The vulnerability resides in the core processing logic of IBM i versions 7.3, 7.4, 7.5, and 7.6, specifically within components handling remote input or protocol parsing.\nThe root cause of the issue stems from a logic flaw where specific malformed or strategically crafted inputs fail to trigger proper termination conditions, steering the execution flow into an unrecoverable infinite loop.\nNetwork exposure is present because the vulnerable functionality is accessible remotely, allowing unauthorized or low-privileged remote adversaries to interact directly with the vulnerable service.\nThe attack flow begins when the remote attacker transmits a specifically crafted payload or sequence of network traffic to the target IBM i system.\nUpon receipt, the vulnerable component processes the input and enters the flawed execution loop due to improper bounds checking, state validation, or error handling.\nAs the routine continuously cycles without yielding execution control or terminating, CPU utilization spikes to maximum capacity, and associated thread or process pools become exhausted.\nThe payload behavior focuses entirely on resource depletion rather than arbitrary code execution or privilege escalation, manifesting strictly as a localized or systemic denial of service.\nPost-exploitation impact includes the total unresponsiveness of the affected service, potential cascading failures across dependent subsystems, and the necessity for administrative intervention, such as a hard service restart or system reboot, to restore normal functionality."
}