Junglewise Threat Intelligence

CVE-2026-17157: IBM AIX and PowerVM VIOS stack buffer overflow remote code execution

CVE-2026-17157 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 are enterprise operating systems used to run mission-critical business applications on IBM Power systems. A stack buffer overflow vulnerability allows remote attackers to execute arbitrary code on affected systems with no authentication required, potentially compromising entire enterprise environments and the applications they host.

Technical details

A stack buffer overflow vulnerability in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allows remote code execution without authentication. The vulnerability is exploitable over the network and permits attackers to execute arbitrary code with the privileges of the vulnerable service. Stack buffer overflows allow attackers to overwrite the call stack and redirect execution to injected shellcode or existing code gadgets. IBM has released security updates via Service Packs and Fix Packs to address this vulnerability; customers are strongly advised to apply these updates promptly to their supported AIX and VIOS releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM Security Bulletin published with vulnerability details and remediation guidance

References

Related threats