Junglewise Threat Intelligence

CVE-2026-19442: IBM AIX pointer validation flaw in Virtual SCSI initiator

CVE-2026-19442 · Severity: high · CVSS 8.2 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS contain a pointer validation flaw in the Virtual SCSI (vSCSI) initiator driver, which is responsible for managing storage device communication. An attacker with local access could exploit this flaw to crash the system, gain elevated privileges, or completely compromise the kernel of virtualized servers running these operating systems.

Technical details

A pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver affecting AIX 7.2, 7.3, and PowerVM VIOS 4.1. The vulnerability allows an attacker with local access to trigger invalid pointer dereferences through crafted vSCSI operations. Successful exploitation may result in denial of service (kernel panic), privilege escalation to root, or arbitrary code execution within the kernel context. The attack vector is local and likely requires at least user-level access to interact with the vSCSI driver. IBM has issued security patches via service packs and fix packs for supported releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with additional installation instructions

References

Related threats