Junglewise Threat Intelligence

CVE-2026-19448: IBM AIX and PowerVM VIOS IPsec ESP stack memory corruption

CVE-2026-19448 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS operating systems contain a memory corruption vulnerability in the IPsec ESP (Encapsulating Security Payload) decapsulation handler. Attackers can exploit this to crash systems and cause service outages, but cannot access or modify data.

Technical details

A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler that processes encrypted network traffic. The vulnerability allows network-based attackers to corrupt kernel stack state through crafted ESP packets. Successful exploitation causes a system crash and denial of service. The vulnerability affects AIX 7.2, 7.3, and PowerVM VIOS 4.1. Patches are available through IBM service packs and fix packs.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • patched: Patches available through IBM service packs and fix packs

References

Related threats