CVE-2026-19086: IBM i is Affected By Multiple Vulnerabilities in PASE [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Other sources
IBM i could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch MJ11517 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch MJ11516 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch MJ11515 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch MJ11514 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MJ11509 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MJ11510 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MJ11511 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MJ11513
Event History
Frequently Asked Questions
Which IBM i releases are identified as affected?
IBM i 7.6, 7.5, 7.4, and 7.3 are identified as potentially affected.
What access does an attacker need to exploit this issue?
The attacker must be authenticated and have local access. No user interaction is required.
What is the practical impact described for exploitation?
Exploitation can cause a denial of service by terminating the authenticated attacker's own PASE process. The provided information does not describe confidentiality or integrity impact.