Junglewise Threat Intelligence

CVE-2026-18828: IBM AIX and PowerVM VIOS stack-based buffer overflow

CVE-2026-18828 · Severity: medium · CVSS 5.4 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a stack-based buffer overflow vulnerability that allows remote attackers to crash affected systems. This could cause service outages for organizations relying on these operating systems for mission-critical infrastructure and virtualization tasks.

Technical details

A stack-based buffer overflow exists in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1, allowing remote attackers to trigger a denial of service condition. The vulnerability is remotely exploitable without authentication or user interaction required. An attacker can send a crafted network request to overflow a stack buffer, causing the affected process to crash and resulting in availability impact. IBM has released security updates through Service Packs and Fix Packs to remediate this issue; affected systems should apply these patches promptly.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats