Junglewise Threat Intelligence

CVE-2026-18822: IBM AIX and PowerVM VIOS denial of service via directory parsing

CVE-2026-18822 · Severity: medium · CVSS 4.4 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a vulnerability in directory record parsing that allows a local attacker to consume excessive system resources, causing the operating system to become unresponsive. This could disrupt critical business operations on servers running these IBM operating systems.

Technical details

The vulnerability is a resource consumption issue (CWE-400-class) in directory parsing logic within IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. A local attacker with system access can trigger uncontrolled resource consumption by crafting malicious directory records, leading to denial of service. The attack requires local access (not network-based) and no special privileges beyond basic user-level access. Successful exploitation results in system unavailability. IBM has released security updates via Service Packs and Fix Packs to remediate this issue.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats