Executive brief
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain an out-of-bounds read vulnerability that could allow a local user with system access to execute arbitrary code with elevated privileges. This affects the core operating system and virtualization layer used in enterprise data centers, potentially compromising the security of all workloads running on the affected systems.
Technical details
An out-of-bounds read vulnerability in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allows a local attacker with user-level privileges to read memory outside intended buffer boundaries. The vulnerability requires local access to the system and user-level privileges to exploit. By reading sensitive kernel or process memory, an attacker can obtain information to bypass security mechanisms and achieve arbitrary code execution in the context of a privileged process. IBM has released security updates through Service Packs and Fix Packs to address this issue.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed