Junglewise Threat Intelligence

CVE-2026-17168: IBM AIX and PowerVM VIOS stack-based buffer overflow

CVE-2026-17168 · Severity: high · CVSS 8.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a stack-based buffer overflow vulnerability that allows an authenticated remote attacker to execute arbitrary code. This could compromise the operating system, allowing an attacker to gain full control of affected servers and the virtual machines running on them.

Technical details

A stack-based buffer overflow vulnerability exists in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. The vulnerability requires remote network access and authentication. An attacker with valid credentials can trigger the overflow to execute arbitrary code at the operating system level, potentially compromising the entire system. IBM has released security updates via Service Packs and Fix Packs to remediate this issue; affected customers should apply these updates promptly.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats