Junglewise Threat Intelligence

CVE-2026-17425: IBM AIX and PowerVM VIOS stack buffer overflow

CVE-2026-17425 · Severity: high · CVSS 7.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a stack buffer overflow vulnerability that allows a remote attacker to cause a denial of service. An exploit would render affected systems temporarily unavailable, disrupting business operations and administrative management capabilities for virtual environments.

Technical details

A stack buffer overflow exists in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1, allowing remote attackers to trigger a denial of service condition. The vulnerability is accessible over the network without authentication or user interaction. Exploitation causes the affected process to crash, resulting in service unavailability. IBM has released security updates delivered through Service Packs (SPs) and Fix Packs (FPs) to remediate this vulnerability.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with additional installation instructions

References

Related threats