Sceawere

Vulnerability Detail

CVE-2026-17255UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i ICMPv6 DoS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
IBM
Product
i
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-04T17:16:53.140Z",
  "pubdate": "2026-09-04T17:16:53.140Z",
  "executiveSummary": "A critical security vulnerability exists in the IBM i TCP/IP stack related to the processing of ICMPv6 Router Advertisement (RA) messages.\nThe vulnerability is characterized by improper validation of the prefix length field within ICMPv6 packets, which can be exploited by a remote, unauthenticated attacker.\nBy sending a maliciously crafted ICMPv6 packet, an attacker can trigger a denial-of-service (DoS) condition, rendering the affected IBM i system unresponsive.\nThe issue affects multiple versions of the operating system, specifically IBM i 7.3, 7.4, 7.5, and 7.6.\nThe primary risk implication is the potential for service disruption, which impacts system availability for legitimate users and applications.\nSuccessful exploitation requires the attacker to have network-level reach to the target IBM i system via IPv6; however, no prior authentication or administrative privileges are necessary to initiate the attack sequence.",
  "technicalDetails": "The vulnerability resides within the IPv6 networking subsystem of the IBM i operating system, specifically within the module responsible for parsing and processing incoming ICMPv6 (Internet Control Message Protocol version 6) messages.\nThe root cause of the flaw is the inadequate boundary checking and validation of the 'prefix length' field contained within the Prefix Information Option (PIO) of an ICMPv6 Router Advertisement message.\nIn the IPv6 stack, Router Advertisements are used by routers to inform hosts about available prefixes for stateless address autoconfiguration. The prefix length field specifies the number of leading bits of the prefix that are valid.\nAn attacker can exploit this by transmitting an ICMPv6 packet containing a malformed or out-of-bounds prefix length value. When the IBM i kernel receives this packet, the validation logic fails to properly sanitize the input before utilizing it in memory operations or internal state updates.\nThe attack flow proceeds as follows: The attacker crafts a malicious ICMPv6 packet with a manipulated prefix length value. This packet is transmitted to the target IBM i system's IPv6 address. Upon receipt, the affected networking component attempts to process the field. Because the input is not sufficiently constrained, it leads to an improper state or a kernel-level exception during the processing phase.\nThis behavior results in a system crash or a hang condition, effectively causing a Denial of Service. The vulnerability does not require the attacker to have established a session, nor does it require any specific user privileges. The exposure is strictly tied to the accessibility of the host's IPv6 interface.\nThis flaw is specific to the handling of the ICMPv6 protocol stack. The impact is limited to availability, as the improper validation logic does not inherently provide a primitive for remote code execution or privilege escalation. However, repeated exploitation could lead to persistent system instability.\nThe vulnerability is present in IBM i 7.3, 7.4, 7.5, and 7.6. The exploitation depends entirely on the host being configured to listen for and process IPv6 Router Advertisement traffic, which is standard behavior for IPv6-enabled nodes."
}
CVE-2026-17255: IBM i ICMPv6 DoS Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere