Junglewise Threat Intelligence

CVE-2026-17122: IBM AIX and PowerVM VIOS stack-based buffer overflow

CVE-2026-17122 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are enterprise operating systems used to run mission-critical business applications on Power Systems infrastructure. A stack-based buffer overflow vulnerability allows a remote attacker to execute arbitrary code without authentication, potentially gaining full control of affected systems and the applications running on them.

Technical details

A stack-based buffer overflow vulnerability exists in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 that allows unauthenticated remote code execution. The vulnerability is exploitable over the network without requiring user interaction or elevated privileges. An attacker can leverage the buffer overflow to overwrite the stack and achieve arbitrary code execution with the privileges of the vulnerable process. IBM has released security updates through Service Packs and Fix Packs to remediate this vulnerability; customers should apply these patches immediately.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats