Executive brief
IBM AIX and PowerVM VIOS are operating systems and virtualization platforms that manage critical enterprise infrastructure. A local attacker with limited system access can exploit an out-of-bounds read vulnerability to disclose sensitive kernel memory, potentially exposing cryptographic keys, authentication tokens, or other confidential operating system data that could be used in further attacks.
Technical details
The vulnerability is an out-of-bounds read affecting AIX 7.2, 7.3 and PowerVM VIOS 4.1, allowing disclosure of sensitive kernel memory. The attack requires local access (authenticated user or process execution on the target system). An attacker can read memory regions beyond intended boundaries, potentially exposing kernel data structures, credentials, or other sensitive information. IBM has released security updates through Service Packs (SPs) and Fix Packs (FPs) to remediate this vulnerability. Patches should be promptly applied to all affected and supported systems.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM security bulletin updated with installation instructions