CVE-2026-16868
Undergoing Analysis Undergoing Analysis - In Progress

Denial of Service in IBM i via ASN.1 Length Processing

Vulnerability report for CVE-2026-16868, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: IBM Corporation

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
ibm ibm_i 7.3
ibm ibm_i 7.4
ibm ibm_i 7.5
ibm ibm_i 7.6
ibm ibm_i From 7.3 (inc)
ibm ibm_i From 7.4 (inc)
ibm ibm_i From 7.5 (inc)
ibm ibm_i From 7.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM i versions 7.6, 7.5, 7.4, and 7.3 are vulnerable to a denial of service attack due to uninitialized memory being used during ASN.1 length processing. This flaw allows a remote attacker to cause system disruptions.

Impact Analysis

This vulnerability can lead to system crashes or service disruptions, potentially causing downtime for affected IBM i systems. It may also allow attackers to execute arbitrary code or gain unauthorized access.

Mitigation Strategies

Apply the latest IBM i PTFs or updates provided by IBM to address the uninitialized memory issue during ASN.1 length processing. Monitor IBM security advisories for patches and test updates in a non-production environment before deployment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16868. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart