Executive brief
IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 are operating systems and virtualization platforms used to run critical business applications. A local attacker with access to the system could exploit a stack-based buffer overflow to execute arbitrary code with the privileges of the affected process, potentially compromising system integrity and confidentiality.
Technical details
A stack-based buffer overflow vulnerability exists in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 that allows local attackers to execute arbitrary code. The vulnerability requires local access and low-level privileges to exploit. An attacker can overflow a stack buffer to corrupt memory and redirect execution flow to attacker-controlled code, achieving arbitrary code execution within the context of the affected application or service. IBM has released security updates through Service Packs (SPs) and Fix Packs (FPs) as described in their security bulletin.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed