Junglewise Threat Intelligence

CVE-2026-17121: IBM AIX and PowerVM VIOS denial of service via uncontrolled recursion

CVE-2026-17121 · Severity: high · CVSS 7.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 are operating systems and virtualization platforms used to run critical business applications. A remote attacker can send specially crafted input that causes uncontrolled recursion, crashing the system and causing a denial of service that disrupts all applications running on the affected infrastructure.

Technical details

The vulnerability is caused by uncontrolled recursion in the affected AIX and PowerVM VIOS releases. An attacker with network access can exploit this by sending malformed input that triggers infinite or deeply nested recursive calls, exhausting stack memory and crashing the operating system. The attack is remotely exploitable without requiring authentication or user interaction. The impact is a complete denial of service affecting all workloads running on the compromised system. IBM has released security patches through Service Packs and Fix Packs to address this vulnerability.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with installation instructions

References

Related threats