
PEACH
Un framework di isolamento del tenant
CVE-2026-18671 is an integer overflow vulnerability in IBM i's NetServer component that allows an attacker to force a server thread exception, resulting in a temporary denial of service. It affects IBM i versions 7.3, 7.4, 7.5, and 7.6. The vulnerability was published on August 13, 2026, and received an NVD CVSS v3.1 base score of 5.3 (Medium), while IBM's own CNA scoring assigns it 6.5 (Medium) (GitHub Advisory, IBM Advisory).
The root cause is an integer overflow or wraparound (CWE-190) that occurs during bounds checking in NetServer request processing on IBM i. When a specially crafted request causes an integer value to exceed its representable range during bounds validation, the resulting incorrect value triggers an unhandled server thread exception. The attack vector is network-based, requires no user interaction, and is automatable according to CISA's SSVC assessment, though exploitation requires authentication per IBM's original description (with NVD's scoring suggesting no privileges required). No public proof-of-concept code has been identified (GitHub Advisory, IBM Advisory).
Successful exploitation causes a temporary denial of service by crashing a NetServer thread on the affected IBM i system. IBM's CNA scoring also indicates a low confidentiality impact (C:L), suggesting limited information disclosure may be possible alongside the availability disruption. The impact is partial and scoped to the affected component, with no integrity impact and no evidence of lateral movement potential (GitHub Advisory, IBM Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code as of the time of disclosure. CISA's SSVC assessment classifies the vulnerability as automatable with partial technical impact and no known exploitation. The EPSS score is approximately 0.22%, placing it in the 13th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, IBM Advisory).
IBM has released a patch addressing this vulnerability, available via the IBM support page for all affected versions (7.3, 7.4, 7.5, and 7.6). Administrators should apply the vendor-supplied fix as soon as possible. As an interim measure if patching is delayed, consider restricting network access to the IBM i NetServer service (e.g., via firewall rules) and monitoring NetServer for unexpected thread exceptions (IBM Advisory).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."