Junglewise Threat Intelligence

CVE-2026-17120: IBM AIX and PowerVM VIOS buffer overflow denial of service

CVE-2026-17120 · Severity: medium · CVSS 5.3 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are enterprise operating systems used to run critical business applications and virtualized workloads. A buffer overflow vulnerability allows a remote attacker to crash these systems, causing service disruption and application downtime without requiring authentication.

Technical details

CVE-2026-17120 is a buffer overflow vulnerability affecting IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. The vulnerability is remotely exploitable without authentication and results in denial of service through system crashes. The exact vulnerable component is not specified in the advisory, but the buffer overflow occurs in a network-reachable code path. IBM has released security updates through Service Packs and Fix Packs to remediate this issue. Affected customers should apply the latest patches promptly.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats