CVE-2026-17273: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
Other sources
IBM i could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11305 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11306 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11307 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11308
Event History
Frequently Asked Questions
Are specific affected IBM i releases identified?
The provided information identifies IBM i but does not list affected or fixed release versions.
Is a mitigation available if patching cannot be completed immediately?
The provided information does not describe any workaround, configuration mitigation, or temporary compensating control.
Are detection guidance or indicators of exploitation provided?
The provided information does not include log indicators, detection methods, or other evidence for identifying exploitation.