Executive brief
IBM AIX and IBM PowerVM VIOS are core operating systems used to run enterprise servers and virtualization infrastructure. An integer overflow vulnerability in size computation allows a remote attacker to execute arbitrary code with high severity, potentially compromising the entire system and all workloads running on it.
Technical details
The vulnerability is an integer overflow during size computation in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. The root cause involves improper handling of size values that can overflow, leading to undersized memory allocations. This allows a remote attacker to achieve arbitrary code execution by exploiting the integer overflow to bypass bounds checks. No authentication or local access is required; the attack can be mounted over the network. A patch is available through IBM service packs and fix packs as described in the security bulletin.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM security bulletin updated with additional installation instructions