Junglewise Threat Intelligence

CVE-2026-17009: IBM AIX and PowerVM VIOS NULL pointer dereference denial of service

CVE-2026-17009 · Severity: medium · CVSS 4.7 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM's AIX operating system and PowerVM VIOS virtualization software contain a vulnerability allowing local users to crash the system through a NULL pointer dereference. A local attacker with basic system access can trigger this flaw to disrupt business operations and availability of critical enterprise infrastructure.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with additional installation instructions

References

Related threats