CVE-2026-17255: IBM i is Affected By Denial of Service Vulnerability []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
Other sources
IBM i could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch MJ11322 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.5Patch MJ11323 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.4Patch MJ11324 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.3Patch MJ11325
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs network access to send crafted ICMPv6 Router Advertisements to the affected IBM i system. No privileges or user interaction are required.
What is the expected impact of successful exploitation?
Successful exploitation can cause a denial of service. The provided information does not indicate confidentiality or integrity impact.
Which IBM i releases are identified as affected?
IBM i 7.3, 7.4, 7.5, and 7.6 are identified as affected.