CVE-2026-17469
Received Received - Intake

Denial of Service in IBM i LPD Queue Name Parser

Vulnerability report for CVE-2026-17469, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: IBM Corporation

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm i From 7.6 (inc)
ibm i From 7.5 (inc)
ibm i From 7.4 (inc)
ibm i From 7.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in IBM i operating systems versions 7.6, 7.5, 7.4, and 7.3. It occurs due to an off-by-one write error in the LPD queue name parser, which could allow a local authenticated attacker to cause system disruption.

Impact Analysis

If exploited, this vulnerability could lead to system instability or unavailability by causing a denial of service. Since it requires local authenticated access, the impact is limited to users with existing system access.

Mitigation Strategies

Apply IBM i PTFs or updates addressing the LPD queue name parser vulnerability. Monitor IBM i security bulletins for patches and restrict local authenticated user access until fixes are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17469. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart