Executive brief
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a stack-based buffer overflow vulnerability that allows an authenticated remote attacker to execute arbitrary code. This could compromise the operating system, allowing an attacker to gain full control of affected servers and the virtual machines running on them.
Technical details
A stack-based buffer overflow vulnerability exists in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. The vulnerability requires remote network access and authentication. An attacker with valid credentials can trigger the overflow to execute arbitrary code at the operating system level, potentially compromising the entire system. IBM has released security updates via Service Packs and Fix Packs to remediate this issue; affected customers should apply these updates promptly.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed