Sceawere

Vulnerability Detail

CVE-2026-18671UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i NetServer Integer Overflow Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-190 Integer Overflow or Wraparound
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T21:17:45.400Z",
  "pubdate": "2026-08-13T21:17:45.400Z",
  "executiveSummary": "An integer overflow vulnerability exists in the NetServer component of IBM i versions 7.6, 7.5, 7.4, and 7.3, potentially leading to a denial of service condition. The flaw arises from improper bounds checking during the parsing and processing of client requests, specifically resulting in an integer overflow that forces a server thread exception.\nThe primary impact of this vulnerability is a temporary denial of service against the targeted NetServer service, disrupting file and print sharing capabilities for legitimate users. Successful exploitation requires an authenticated attacker with network access to interact with the NetServer component.\nThe attacker must possess valid authentication credentials to establish a session and submit maliciously crafted requests designed to trigger the boundary calculation error. No privilege escalation or remote code execution capabilities are granted through this specific vector, as the direct consequence is restricted to thread termination and localized service disruption.\nRisk implications include potential operational downtime for dependent file and print operations on the affected IBM i systems. Organizations utilizing the impacted versions must evaluate their exposure and apply available vendor supplied fixes or workarounds to maintain service availability and integrity.",
  "technicalDetails": "The vulnerability resides within the NetServer request processing subsystem of IBM i versions 7.6, 7.5, 7.4, and 7.3. The root cause of the issue is an integer overflow condition that occurs during explicit bounds checking routines when the application validates incoming request lengths or offsets.\nDuring standard protocol handling, the NetServer component calculates buffer sizes and memory offsets to process incoming client payloads. If an authenticated attacker supplies carefully manipulated request parameters designed to exceed standard numerical boundaries, an integer overflow is triggered within the size calculation logic.\nThe attack flow proceeds as follows: First, the authenticated attacker establishes a network connection to the NetServer service running on the targeted IBM i host. Second, the attacker transmits a specially crafted request containing boundary parameters engineered to induce an integer overflow during the internal validation phase. Third, the bounds checking mechanism fails to accurately evaluate the oversized or wrapped integer value, allowing the execution flow to proceed with invalid memory offsets or buffer allocations.\nThis calculation failure immediately results in an unhandled exception within the specific NetServer server thread handling the request. The resultant thread exception forces the termination of the affected thread, culminating in a temporary denial of service for clients attempting to utilize that specific server process or session.\nPrerequisites for exploitation include network exposure to the NetServer service and valid authentication credentials to interact with the IBM i environment. The vulnerability is strictly confined to a denial of service impact, with no evidence of memory corruption leading to arbitrary code execution or unauthorized data disclosure based on the provided vulnerability scope."
}
CVE-2026-18671: IBM i NetServer Integer Overflow Denial of Service (MEDIUM Severity, CVSS: 6.5) - Sceawere