Executive brief
IBM AIX and PowerVM VIOS are enterprise operating systems used to run business-critical applications and manage virtualized IT infrastructure. A local attacker with system access can exploit a stack-based buffer overflow to execute arbitrary code with the privileges of the affected process, potentially gaining control of the system and accessing sensitive data.
Technical details
This vulnerability is a stack-based buffer overflow in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. The vulnerability requires local access and authenticated user privileges to exploit. An attacker with local system access can craft input to overflow a stack buffer, overwrite return addresses or other stack data, and redirect execution flow to attacker-controlled code. Successful exploitation allows arbitrary code execution at the privilege level of the vulnerable process. IBM has released security updates through Service Packs and Fix Packs to remediate this issue.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed: CVE-2026-16945 disclosed