Skip to content
Threat Feed
medium advisory

Integer Underflow Vulnerability in IBM i

IBM i versions 7.3 through 7.6 are vulnerable to an integer underflow flaw (CVE-2026-17485) that could allow a remote, unauthenticated attacker to cause a denial of service or perform an out-of-bounds read to access sensitive information.

CVE search metadata

CVE search record: CVE-2026-17485. Severity: high. CVSS: 8.2. KEV: no. Product: i. Brief: Integer Underflow Vulnerability in IBM i. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-i-integer-underflow/

IBM has disclosed a critical integer underflow vulnerability (CVE-2026-17485) affecting IBM i operating system versions 7.3, 7.4, 7.5, and 7.6. This vulnerability arises from an integer underflow condition, categorized as CWE-125 (Out-of-bounds Read). The flaw allows a remote, unauthenticated attacker with network access to the target system to trigger a denial of service (DoS) condition or gain unauthorized access to sensitive information. Given the CVSS v3.1 base score of 8.2 and the potential for unauthenticated remote exploitation, this poses a significant risk to organizations running these versions of IBM i. Defenders should prioritize applying the security updates provided by IBM to mitigate the risk of service disruption and data exposure.

Impact

Successful exploitation of this vulnerability could lead to significant operational disruption through service crashes (denial of service) and potential unauthorized disclosure of sensitive system memory contents. The vulnerability affects a wide range of enterprise environments currently utilizing IBM i versions 7.3 through 7.6.

Recommendation

  • Apply the security patches referenced in IBM Security Bulletin APAR node 7282695 immediately to all affected IBM i systems.
  • Review network configurations to restrict unauthorized remote access to IBM i services, as the vulnerability is exploitable by remote, unauthenticated attackers.
  • Audit system logs for unexpected service restarts or abnormal memory access errors that may indicate exploitation attempts.

Immediate actions

Patch IBM i versions 7.3-7.6 using the updates specified in IBM support node 7282695.

IT Operations 48h