Executive brief
IBM AIX and PowerVM VIOS are operating systems used to run enterprise workloads and critical business applications. A buffer overflow vulnerability allows a remote attacker without authentication to execute arbitrary code with system privileges, potentially compromising all data and operations on affected servers.
Technical details
CVE-2026-17152 is a buffer overflow vulnerability in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 that permits unauthenticated remote code execution. The vulnerability is reachable over the network without requiring authentication or user interaction, making it immediately exploitable. An attacker can leverage this flaw to achieve complete system compromise with elevated privileges. IBM has released security patches through Service Packs and Fix Packs as described in their security bulletin; customers should promptly apply available updates to affected releases.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM security bulletin updated with installation instructions