CVE-2026-18078: IBM i is Affected By Denial of Service Vulnerability in Save Restore []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
Other sources
IBM i could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11369 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11368 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11367 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11366
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remote and authenticated, meaning they need valid access to the affected IBM i environment. No user interaction is required.
Which IBM i releases are identified as affected?
IBM i 7.3, 7.4, 7.5, and 7.6 are listed as affected.
What is the expected impact of successful exploitation?
Successful exploitation can cause a denial of service. The provided impact information indicates availability impact only, with no stated confidentiality or integrity impact.