Executive brief
IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 are operating system and virtualization software used in enterprise data centers. A remote attacker can exploit an integer overflow flaw to crash these systems, causing service outages and operational disruption without requiring authentication.
Technical details
An integer overflow vulnerability in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 allows a remote, unauthenticated attacker to trigger a denial of service condition. The vulnerability stems from improper handling of integer arithmetic in a network-reachable component, enabling an attacker to craft a malicious input that causes integer wraparound and subsequent system crash or hang. No user interaction is required; exploitation occurs via network vector. Patches are available through IBM security updates and service packs.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: other: IBM security bulletin updated with remediation details