CVE-2026-17057: IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
Other sources
IBM i could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11320 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ11319 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ11318 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.3Patch SJ11317
Event History
Frequently Asked Questions
Which IBM i releases are affected?
IBM i 7.6, 7.5, 7.4, and 7.3 are identified as affected.
Does exploitation require authentication or user interaction?
No. The vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What security impact can exploitation have?
A remote attacker could cause a denial of service and affect data integrity. The stated impact does not include confidentiality loss.