Junglewise Threat Intelligence

CVE-2026-17060: IBM AIX and PowerVM VIOS kernel heap over-read

CVE-2026-17060 · Severity: high · CVSS 8.1 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are Unix-based operating systems used to run enterprise workloads on IBM Power Systems servers. A kernel heap over-read vulnerability allows a remote attacker to leak sensitive system memory and cause service outages, potentially exposing cryptographic keys, configuration data, or other confidential information stored in kernel memory.

Technical details

The vulnerability is a kernel heap over-read flaw in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 that permits a remote attacker to read beyond allocated heap boundaries. This memory disclosure can expose sensitive kernel data including cryptographic material or system secrets. The same flaw can also be leveraged to trigger a denial of service by corrupting kernel memory state. The vulnerability is reachable over the network and does not appear to require authentication or user interaction. IBM has released security updates through Service Packs and Fix Packs to remediate this issue in supported releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed: CVE-2026-17060 published on NVD
  • 2026-08-21: advisory: IBM Security Bulletin updated with remediation guidance

References

Related threats