CVE-2026-17469: IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
Other sources
IBM i could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11300 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11301 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11302 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11303
Event History
Frequently Asked Questions
Which IBM i releases are identified as affected?
IBM i 7.3, 7.4, 7.5, and 7.6 are identified as affected.
Does exploitation require network access or authentication?
The vulnerability is described as requiring a local, authenticated attacker. The provided data does not describe unauthenticated or remote exploitation.
What is the expected impact if exploited?
An attacker could cause a denial of service. The provided severity vector indicates availability impact only, with no stated confidentiality or integrity impact.