Sceawere

Vulnerability Detail

CVE-2026-17212UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Out-of-Bounds Read Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-125 Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-13T21:17:42.290Z",
  "pubdate": "2026-08-13T21:17:42.290Z",
  "executiveSummary": "IBM i versions 7.6, 7.5, 7.4, and 7.3 contain an out-of-bounds read vulnerability that could allow a remote attacker to cause a denial of service condition.\nThe vulnerability stems from improper bounds checking within memory handling operations, leading to an out-of-bounds read when processing specific inputs.\nSuccessful exploitation of this flaw allows an unauthenticated remote adversary to crash affected services or trigger system instability, resulting in a complete denial of service for legitimate users.\nThe risk implication is significant as it disrupts system availability without requiring elevated privileges or user interaction, provided the vulnerable service is exposed to the network.\nDefense strategies rely on applying official vendor patches and restricting network access to susceptible services to mitigate potential exposure.",
  "technicalDetails": "The vulnerability is classified as an out-of-bounds read, originating from a failure in the application logic to correctly validate the length and boundaries of input data prior to memory read operations.\nAffected products include IBM i 7.6, 7.5, 7.4, and 7.3, specifically impacting underlying components responsible for parsing network packets or handling specific protocol requests.\nAttackers can leverage network exposure to interact directly with the vulnerable service by sending a specially crafted sequence of bytes or malformed payloads designed to trigger the out-of-bounds read condition.\nDuring the attack flow, the vulnerable component attempts to read memory past the allocated buffer boundary. Depending on the memory architecture and adjacent data structures, this operation results in an immediate exception, process termination, or service crash.\nThe exploitation vector is entirely remote, requiring network connectivity to the target service. No authentication or local privilege requirements are necessary to initiate the attack.\nThe payload behavior is focused strictly on causing a denial of service through abnormal termination rather than arbitrary code execution or privilege escalation, as the memory flaw manifests as a read violation rather than a write/overflow condition.\nPost-exploitation impact is limited to service unavailability, requiring administrative intervention to restart the affected daemons or systems, though repeated exploitation can lead to prolonged outages."
}
CVE-2026-17212: IBM i Out-of-Bounds Read Denial of Service (MEDIUM Severity, CVSS: 5.3) - Sceawere