Sceawere

Vulnerability Detail

CVE-2026-18077UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Buffer Overflow Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-13T21:17:44.230Z",
  "pubdate": "2026-08-13T21:17:44.230Z",
  "executiveSummary": "This vulnerability involves a stack-based buffer overflow flaw present in IBM i versions 7.6, 7.5, 7.4, and 7.3. The security defect exposes the affected systems to remote denial of service attacks.\nA remote attacker can exploit this vulnerability by sending specially crafted inputs to the vulnerable component, triggering a stack-based buffer overflow condition.\nSuccessful exploitation compromises system availability, leading to potential service crashes or system destabilization on the targeted IBM i environment.\nThe risk implication is significant for organizations running the affected operating system versions, as service disruption can impact critical business workloads.\nThe attack vector is network-based, allowing unauthorized or remote threat actors to initiate the attack sequence without requiring complex privileges, depending on the exposure of the vulnerable service.",
  "technicalDetails": "The vulnerability stems from a stack-based buffer overflow condition residing within the underlying architecture of IBM i 7.6, 7.5, 7.4, and 7.3.\nThe root cause is characterized by insufficient bounds checking when processing incoming data streams or parameters within the vulnerable component, allowing input data to exceed the allocated boundaries of a fixed-size stack buffer.\nDuring the attack flow, a remote threat actor transmits a maliciously crafted payload across the network to the targeted service.\nAs the vulnerable application parses the input, the excessive data overflows the stack buffer, overwriting adjacent memory structures, including saved frame pointers and return addresses.\nThis memory corruption results in an immediate exception or segmentation fault, causing the targeted service or the entire operating system environment to crash, thereby achieving a denial of service.\nThe affected product versions include IBM i 7.6, 7.5, 7.4, and 7.3.\nExploitation requires network access to the vulnerable service running on the target system.\nDepending on the specific network exposure of the affected daemon or interface, the attack can typically be executed remotely by an unauthenticated attacker, resulting in service interruption and system unavailability."
}
CVE-2026-18077: IBM i Buffer Overflow Denial of Service (HIGH Severity, CVSS: 7.5) - Sceawere