Junglewise Threat Intelligence

CVE-2026-16952: IBM AIX and PowerVM VIOS denial of service from resource exhaustion

CVE-2026-16952 · Severity: medium · CVSS 5.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a vulnerability that allows local users to exhaust system resources and cause the operating system to become unavailable. An attacker with local access can trigger uncontrolled resource consumption, forcing a service restart and disrupting business operations that depend on these critical virtualization platforms.

Technical details

The vulnerability stems from uncontrolled resource consumption in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. A local attacker with limited privileges (PR:L) can trigger resource exhaustion without user interaction, leading to denial of service. The attack vector is local-only, requiring authentication or shell access to the affected system. Successful exploitation causes unavailability (A:H) of the operating system but does not compromise confidentiality or integrity. Patches are available through IBM service packs and fix packs; customers should apply updates promptly through supported maintenance channels.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats