Executive brief
IBM AIX and PowerVM VIOS are enterprise operating systems used to run critical business applications and virtualized workloads. A buffer overflow vulnerability allows a remote attacker to crash these systems, causing service disruption and application downtime without requiring authentication.
Technical details
CVE-2026-17120 is a buffer overflow vulnerability affecting IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. The vulnerability is remotely exploitable without authentication and results in denial of service through system crashes. The exact vulnerable component is not specified in the advisory, but the buffer overflow occurs in a network-reachable code path. IBM has released security updates through Service Packs and Fix Packs to remediate this issue. Affected customers should apply the latest patches promptly.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed