Sceawere

Vulnerability Detail

CVE-2026-17271UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Input Size Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1h ago
Vendor
IBM
Product
i
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-12T18:17:26.557Z",
  "pubdate": "2026-08-12T18:17:26.557Z",
  "executiveSummary": "A denial of service vulnerability exists in IBM i versions 7.6, 7.5, 7.4, and 7.3, stemming from improper validation of input size within the operating system. This security flaw enables a remote attacker to induce system instability or service unavailability by supplying oversized or improperly constrained input parameters to vulnerable application components. The primary operational impact is the disruption of system availability, potentially halting critical business processes hosted on the affected IBM i environments. The risk implication centers on operational resilience, as attackers can repeatedly trigger the fault to maintain a persistent denial of service state. Exploitation requires network connectivity to the targeted service and does not inherently depend on advanced attacker capabilities beyond crafting malicious input payloads designed to trigger the bounds violation or resource exhaustion condition.",
  "technicalDetails": "The vulnerability root cause resides in the lack of rigorous boundary checking and input size validation mechanisms within specific parser or handler routines in IBM i 7.6, 7.5, 7.4, and 7.3. When an interacting client transmits a sequence of data over the network, the underlying subsystem processes the payload without appropriately verifying whether the declared or actual input length conforms to pre-allocated buffer thresholds or internal architectural constraints. Exploitation occurs when a remote, unauthenticated or authenticated attacker constructs a specialized payload containing an excessively large input size attribute or data stream. Upon transmission to the vulnerable network service, the target component ingests the unvalidated data, resulting in abnormal memory manipulation, excessive resource consumption, or fatal exception handling that crashes the service or degrades the operating system's operational capacity. The attack flow begins with network reconnaissance to identify accessible services on the IBM i host, followed by the transmission of the maliciously crafted input packet designed to bypass input verification checks. The vulnerable component fails to gracefully reject the oversized input, directly provoking a denial of service condition. Network exposure is present wherever vulnerable services are reachable by potential threat actors. Privilege and authentication requirements depend on the specific exposed service, but the fundamental flaw lies in the inadequate sanitization and size enforcement of incoming data streams."
}
CVE-2026-17271: IBM i Input Size Denial of Service (HIGH Severity, CVSS: 7.5) - Sceawere