Executive brief
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain an out-of-bounds write vulnerability that allows local attackers to crash the system or cause service disruptions. This affects the core operating systems used to manage enterprise virtualization and data center infrastructure, potentially impacting business continuity and operational availability.
Technical details
This vulnerability is an out-of-bounds write issue in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 that can be exploited by a local attacker with limited privileges. The attack requires local access and no user interaction. Successful exploitation results in denial of service through system crash or service termination. IBM has released security updates via Service Packs (SPs) and Fix Packs (FPs) to remediate this vulnerability; customers should apply these updates promptly as recommended in the security bulletin.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM security bulletin updated with additional installation instructions