CVE-2026-19280: IBM i is Affected By Multiple Vulnerabilities in PASE [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Other sources
IBM i could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6 (PASE)to a version that resolves this vulnerability.Patch MJ11517 - Upgrade
Upgrade
IBM i 7.5 (PASE)to a version that resolves this vulnerability.Patch MJ11516 - Upgrade
Upgrade
IBM i 7.4 (PASE)to a version that resolves this vulnerability.Patch MJ11515 - Upgrade
Upgrade
IBM i 7.3 (PASE)to a version that resolves this vulnerability.Patch MJ11514
Event History
Frequently Asked Questions
Which IBM i releases are affected?
IBM i 7.6, 7.5, 7.4, and 7.3 are listed as affected.
What access does an attacker need to exploit this issue?
The attacker must be authenticated and have local access. No user interaction is required.
What is the practical impact described for exploitation?
An authenticated attacker can trigger a buffer overflow in a PASE process and terminate their own process, resulting in a denial of service.