Executive brief
IBM AIX and PowerVM VIOS are core operating systems that run enterprise servers and virtualization infrastructure. A flaw allows authenticated remote attackers to read sensitive data from memory or crash the system, potentially exposing confidential information or disrupting critical business operations.
Technical details
The vulnerability is an out-of-bounds read in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. It requires remote network access and prior authentication. An attacker can exploit this to leak sensitive information from process memory or trigger a denial of service condition. IBM has released security updates as part of cumulative maintenance packages; customers should apply Service Packs or Fix Packs promptly. The exact vulnerable component is not detailed in available documentation.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed