Executive brief
IBM AIX and PowerVM VIOS are operating systems used to run critical business applications and virtualized workloads on Power Systems servers. A remote attacker can send a specially crafted UDP packet to an exposed RPC service, causing the entire system to become unavailable and requiring a manual restart. This vulnerability allows anyone on the network to disrupt operations without needing valid credentials.
Technical details
This vulnerability is a remote denial-of-service (DoS) condition in the RPC service component of IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. An unauthenticated attacker can craft a malformed UDP packet targeting a reachable RPC endpoint, triggering a crash or hang that renders the system completely unavailable and requires an LPAR (logical partition) restart to recover. The attack vector is network-based with no authentication required, making it broadly exploitable if RPC services are exposed. Patches are available through IBM service packs and fix packs.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed