Junglewise Threat Intelligence

CVE-2026-16958: IBM AIX and PowerVM VIOS out-of-bounds write denial of service

CVE-2026-16958 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain an out-of-bounds write vulnerability that allows a remote attacker to crash or destabilize these critical operating systems and virtualization platforms. A successful attack could interrupt business operations by causing service outages on systems running these operating systems.

Technical details

This vulnerability is an out-of-bounds write condition affecting IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. The root cause and specific vulnerable component are not detailed in the advisory, but the flaw allows a remote attacker to write data outside allocated memory bounds. The attack is network-accessible without requiring prior authentication. Successful exploitation results in denial of service, likely through process crash or system instability. IBM has released security updates as Service Packs (SPs) and Fix Packs (FPs) to remediate the vulnerability.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats