Executive brief
IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 are operating systems and virtualization platforms used to run critical business applications. A remote attacker can send specially crafted input that causes uncontrolled recursion, crashing the system and causing a denial of service that disrupts all applications running on the affected infrastructure.
Technical details
The vulnerability is caused by uncontrolled recursion in the affected AIX and PowerVM VIOS releases. An attacker with network access can exploit this by sending malformed input that triggers infinite or deeply nested recursive calls, exhausting stack memory and crashing the operating system. The attack is remotely exploitable without requiring authentication or user interaction. The impact is a complete denial of service affecting all workloads running on the compromised system. IBM has released security patches through Service Packs and Fix Packs to address this vulnerability.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM security bulletin updated with installation instructions