Junglewise Threat Intelligence

CVE-2026-17165: IBM AIX and PowerVM VIOS NULL pointer dereference denial of service

CVE-2026-17165 · Severity: high · CVSS 7.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are core operating system and virtualization components used to run business-critical applications in enterprise data centers. A remote attacker can cause these systems to crash by triggering a NULL pointer dereference, leading to service outages and business disruption without requiring authentication or special access.

Technical details

This vulnerability is a NULL pointer dereference in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 that allows a remote attacker to trigger a denial of service condition. The root cause involves improper null pointer validation in a network-accessible component, which can be exploited without authentication. An attacker can send a specially crafted remote request that causes the affected system to dereference a null pointer, resulting in a process crash or system hang. IBM has released security updates through Service Packs and Fix Packs for supported releases under active fix support.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with installation instructions

References

Related threats