CVE-2026-17207: IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
Other sources
IBM i could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11320 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11319 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11318 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11317
Event History
Frequently Asked Questions
Which IBM i releases are identified as affected?
The affected releases listed are IBM i 7.6, 7.5, 7.4, and 7.3.
Can this be exploited remotely without authentication or user interaction?
Yes. The vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What security impact is described?
The issue could allow a remote attacker to cause denial of service and compromise integrity due to a buffer overflow. No confidentiality impact is indicated by the provided vector.