Junglewise Threat Intelligence

CVE-2026-19446: IBM AIX and PowerVM VIOS RPC DoS via malformed UDP packet

CVE-2026-19446 · Severity: high · CVSS 7.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are operating systems used to run critical business applications and virtualized workloads on Power Systems servers. A remote attacker can send a specially crafted UDP packet to an exposed RPC service, causing the entire system to become unavailable and requiring a manual restart. This vulnerability allows anyone on the network to disrupt operations without needing valid credentials.

Technical details

This vulnerability is a remote denial-of-service (DoS) condition in the RPC service component of IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. An unauthenticated attacker can craft a malformed UDP packet targeting a reachable RPC endpoint, triggering a crash or hang that renders the system completely unavailable and requires an LPAR (logical partition) restart to recover. The attack vector is network-based with no authentication required, making it broadly exploitable if RPC services are exposed. Patches are available through IBM service packs and fix packs.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats