Sceawere
Vulnerability Detail
CVE-2026-17229UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Denial of Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-13T20:17:19.267Z",
"pubdate": "2026-08-13T20:17:19.267Z",
"executiveSummary": "An infinite loop vulnerability exists in IBM i versions 7.6, 7.5, 7.4, and 7.3, potentially allowing a remote attacker to cause a denial of service.\nThe vulnerability directly impacts system availability by inducing resource exhaustion through unhandled execution paths.\nAttack capabilities involve remote triggering of the condition, leading to severe performance degradation or complete service unresponsiveness.\nRisk implications include operational disruption of critical business systems relying on the affected IBM i platform.\nExploitation requirements are limited to network connectivity to the vulnerable service capable of triggering the logic flaw resulting in the infinite loop state.",
"technicalDetails": "The vulnerability stems from a logical flaw in the affected software components of IBM i versions 7.6, 7.5, 7.4, and 7.3, which fails to properly validate or bound iterative execution paths.\nWhen a remote attacker interacts with the vulnerable component using specifically crafted network input, the application enters an unrecoverable infinite loop.\nThis execution anomaly traps system threads, consuming maximal CPU cycles and exhausting critical processing resources.\nThe attack flow proceeds as follows: the attacker establishes a network connection to the target service, transmits a malicious payload designed to trigger the flawed parsing or processing logic, and the application subsequently fails to break out of the iterative cycle.\nAuthentication and privilege requirements depend on the specific exposed service handling the request, but the capability is exposed to remote threat actors.\nThe post-exploitation impact is strictly confined to a denial of service, preventing legitimate users and administrators from accessing system services until manual intervention, such as process termination or system reboot, is performed."
}