Executive brief
IBM AIX and PowerVM VIOS are operating systems used to run critical business applications and virtual environments in enterprise data centers. A local attacker with access to the system can exploit an out-of-bounds read vulnerability to either extract sensitive information from memory or crash the system, disrupting operations.
Technical details
CVE-2026-17007 is an out-of-bounds read vulnerability affecting IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. The vulnerability allows a local attacker to read memory beyond intended boundaries, potentially exposing sensitive data or causing a denial of service. Attack requires local access to the affected system. The vulnerability enables information disclosure and availability impact. IBM has published security updates through service packs and fix packs to remediate the issue.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed: CVE-2026-17007 published
- 2026-08-21: patched: IBM released security updates through service packs and fix packs