Executive brief
IBM AIX and PowerVM VIOS are operating systems and virtualization platforms used to run critical enterprise applications. A remote attacker can crash these systems by sending specially crafted network packets that exploit improper validation of array size fields, causing service outages and business disruption.
Technical details
The vulnerability exists in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1, where improper validation of an array size field allows a remote attacker to trigger a denial of service condition. The vulnerability is remotely exploitable with no authentication required (CVSS attack vector: network). An attacker can craft malicious input that bypasses array size validation, causing the system to crash or become unresponsive. IBM has released security updates as part of cumulative maintenance packages and service/fix packs to remediate this issue.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed