Junglewise Threat Intelligence

CVE-2026-17160: IBM AIX and PowerVM VIOS integer overflow in size computation

CVE-2026-17160 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and IBM PowerVM VIOS are core operating systems used to run enterprise servers and virtualization infrastructure. An integer overflow vulnerability in size computation allows a remote attacker to execute arbitrary code with high severity, potentially compromising the entire system and all workloads running on it.

Technical details

The vulnerability is an integer overflow during size computation in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. The root cause involves improper handling of size values that can overflow, leading to undersized memory allocations. This allows a remote attacker to achieve arbitrary code execution by exploiting the integer overflow to bypass bounds checks. No authentication or local access is required; the attack can be mounted over the network. A patch is available through IBM service packs and fix packs as described in the security bulletin.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with additional installation instructions

References

Related threats