Junglewise Threat Intelligence

CVE-2026-16924: IBM AIX and PowerVM VIOS IPsec denial of service

CVE-2026-16924 · Severity: high · CVSS 7.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are enterprise operating systems and virtualization platforms used to run critical business applications. A flaw in how these systems process IPsec-encrypted network traffic can allow a remote attacker to crash the system, causing service disruption and potential downtime for dependent applications and services.

Technical details

The vulnerability exists in the IPsec decapsulation code in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1. An improper calculation of a memory offset during IPsec packet processing can be exploited by a remote attacker to trigger a denial of service condition. The attack does not require authentication or special privileges and is triggered via crafted IPsec packets over the network. Successful exploitation results in a system crash or hang, disrupting normal operations. IBM has released security updates through Service Packs and Fix Packs to remediate this issue.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats