Executive brief
IBM AIX (versions 7.2 and 7.3) and IBM PowerVM VIOS 4.1 are enterprise operating systems and virtualization platforms used to run critical business applications. A time-of-check to time-of-use race condition vulnerability allows any local user to gain elevated system privileges, potentially leading to complete compromise of the server and any workloads running on it.
Technical details
This vulnerability exploits a TOCTOU (time-of-check to time-of-use) race condition in the affected AIX and PowerVM VIOS kernels or system components. The vulnerability requires local access to the system and allows an unprivileged local attacker to escalate privileges to root or administrator level. By leveraging a window of time between a privilege check and the actual use of a resource, an attacker can manipulate system state to bypass authorization controls. No network access is required; the attacker must already have local user access to the system to execute the exploit.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed