CVE-2026-17077: IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.
Other sources
IBM i could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i (Release5770-SS1)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ10848 - Upgrade
Upgrade
IBM i (Release5770-SS1)to a version that resolves this vulnerability.Fixed in 7.5Patch SJ10849 - Upgrade
Upgrade
IBM i (Release5770-SS1)to a version that resolves this vulnerability.Fixed in 7.4Patch SJ10850 - Upgrade
Upgrade
IBM i (Release5770-SS1)to a version that resolves this vulnerability.Fixed in 7.3Patch SJ10851
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17077?
The severity of CVE-2026-17077 is medium with a score of 5.3.
What impact does CVE-2026-17077 have?
CVE-2026-17077 could allow a remote attacker to cause a denial of service.
Which versions of IBM i are affected by CVE-2026-17077?
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected by CVE-2026-17077.
How can organizations mitigate the risk of CVE-2026-17077?
Organizations should apply relevant patches and updates to IBM i systems to mitigate the risk of CVE-2026-17077.
What is the cause of the vulnerability in CVE-2026-17077?
CVE-2026-17077 is caused by the use of an uninitialized variable in IBM i.