Sceawere

Vulnerability Detail

CVE-2026-19280UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i PASE Buffer Overflow

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.2
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.2",
  "pubDate": "2026-09-14T21:17:04.627Z",
  "pubdate": "2026-09-14T21:17:04.627Z",
  "executiveSummary": "This vulnerability involves a buffer overflow flaw identified within a Portable Application Solutions Environment (PASE) process on IBM i systems. The defect permits an authenticated attacker to trigger an abnormal termination of their own process, resulting in a localized denial of service (DoS).\nAffected products include IBM i versions 7.3, 7.4, 7.5, and 7.6. The risk is primarily confined to process-level availability, as the vulnerability enables authenticated users to disrupt the execution flow of their own session environment.\nExploitation requires the attacker to possess authenticated access to the system. While the scope of the impact is technically limited to the attacker's own process, such flaws often indicate underlying memory corruption issues that require immediate attention through vendor-supplied patches to maintain system integrity and stability.",
  "technicalDetails": "The root cause of this vulnerability is a buffer overflow condition present within a PASE process on the IBM i operating system. PASE (Portable Application Solutions Environment) provides an AIX-compatible runtime environment on IBM i, which executes in a restricted user-mode space but interfaces with the underlying Licensed Internal Code (LIC).\nA buffer overflow occurs when a process attempts to write data beyond the boundaries of a pre-allocated memory buffer. In this instance, the vulnerability exists within the logic handling input within a PASE-specific process. By providing crafted input that exceeds the expected bounds of a buffer, an attacker can overwrite adjacent memory locations, including critical control data or execution pointers.\nThe attack flow proceeds as follows: First, the attacker must establish an authenticated session on the IBM i system. Second, the attacker interacts with the specific vulnerable PASE component, supplying malicious data designed to exceed the capacity of an internal stack or heap buffer. Third, upon processing this data, the memory corruption leads to an unhandled exception or illegal memory access, causing the operating system to forcefully terminate the offending process.\nAlthough the current threat intelligence suggests that the impact is limited to the termination of the attacker's own process, the underlying mechanism is a classic memory corruption vulnerability. Such flaws are significant because they represent a failure in boundary checking and input validation within the PASE runtime. If the corrupted memory includes function pointers or return addresses, an attacker might theoretically manipulate control flow; however, the reported primary impact remains a denial of service.\nThe vulnerability affects all supported IBM i versions: 7.3, 7.4, 7.5, and 7.6. The exploitation is local, as it necessitates the ability to execute code within the PASE environment. The attacker does not necessarily require high-level administrative privileges, as the process-level crash is localized to the user context. This necessitates careful oversight of user permissions and the monitoring of system logs for unusual process termination patterns."
}
CVE-2026-19280: IBM i PASE Buffer Overflow (MEDIUM Severity, CVSS: 5.2) | Sceawere