Junglewise Threat Intelligence

CVE-2026-17141: IBM AIX buffer overflow in NIM

CVE-2026-17141 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are operating systems used to manage critical enterprise infrastructure. A buffer overflow vulnerability in the NIM (Network Install Manager) component allows remote attackers to execute arbitrary code with system privileges, potentially compromising server availability, data integrity, and enabling lateral movement across infrastructure.

Technical details

The vulnerability is a buffer overflow in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 NIM, triggered by remote network traffic without authentication required. The NIM service fails to properly validate input length before writing to a fixed-size buffer, allowing an attacker to overwrite memory and execute arbitrary code at the privileges of the NIM daemon. The CVSS score of 9.8 indicates network-adjacent attack vector with no authentication or user interaction required. IBM has released security updates through Service Packs and Fix Packs to remediate this and related vulnerabilities.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed: CVE-2026-17141 published
  • 2026-08-21: patched: IBM released security updates via Service Packs and Fix Packs

References

Related threats