Executive brief
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain an out-of-bounds read vulnerability that allows remote attackers to access sensitive information and trigger service outages. This vulnerability affects critical enterprise infrastructure used to manage virtualization and operating system environments across organizations.
Technical details
The vulnerability is an out-of-bounds read in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1. The root cause and vulnerable component details are not fully disclosed in available summaries. The attack vector is network-based, allowing remote attackers without authentication to exploit the flaw. Successful exploitation enables information disclosure (reading sensitive data from memory) and denial of service. IBM has released security updates through Service Packs (SPs) and Fix Packs (FPs) to remediate this issue, and customers are advised to apply patches promptly.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed: CVE-2026-17423 published on NVD
- 2026-08-21: advisory: IBM Security Bulletin updated with remediation guidance