ZeroHour

CVE-2026-17255

large

Out-of-bounds Write DoS in IBM i via crafted ICMPv6 Router Advertisements

CVSS 3.1
7.5 high
EPSS
<1%p34
Published
()
Modified
AI analysis

IBM i releases 7.3 through 7.6 improperly validate the prefix length field in ICMPv6 Router Advertisement messages, an out-of-bounds write (CWE-787) in the operating system's IPv6 processing. An attacker who can deliver a specially crafted Router Advertisement with an invalid prefix length to an affected system can trigger the flaw without authentication or user interaction (AV:N/AC:L/PR:N/UI:N per the CVSS vector; note that Router Advertisements are normally processed on the local link, so practical exposure is limited to networks where the attacker can inject such packets). The impact is denial of service only: availability impact is rated high, while confidentiality and integrity are unaffected. Any IBM i partition running release 7.3, 7.4, 7.5, or 7.6 with IPv6 enabled is affected. There is no known exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS assigns a low 0.4% probability of exploitation within 30 days (34th percentile).

What to do: Install the corrective PTFs listed in IBM's security bulletin for your IBM i release (7.3, 7.4, 7.5, or 7.6) as soon as they are available. Until then, restrict untrusted ICMPv6 Router Advertisements on network segments hosting IBM i systems (e.g., switch RA Guard or filtering so only authorized routers originate RAs), and check whether IPv6 is actually in use on affected partitions since systems without IPv6 enabled are not reachable by this flaw. Monitor IBM's bulletin for updated fix information and consider this a likely local-segment attack vector given the Router Advertisement trigger.

Affected
IBM i7.3, 7.4, 7.5, 7.6
Estimated exposure
largetens of thousands of IBM i systems (installed base commonly cited at ≈100,000+ customer sites; only the IPv6-enabled subset is exposed) — IBM i's installed base is widely reported at roughly 100,000+ customer sites, and releases 7.3–7.6 span the currently deployed and supported base, but exposure requires IPv6 enabled and reachability for attacker-supplied Router…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.

Vendors
ibm
Products
i
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.