Executive brief
IBM AIX and PowerVM VIOS operating systems contain a vulnerability in their filesystem directory reading code that can be triggered by a specially crafted filesystem image. A local attacker can exploit this to corrupt kernel memory, causing the system to crash or potentially gain elevated privileges. This affects core operating system functionality that manages system resources and data integrity.
Technical details
The vulnerability is a memory safety issue (insufficient validation) in the directory reading path of IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. A crafted filesystem image triggers an out-of-bounds write to the kernel stack during directory traversal operations. The attack requires local system access (not remotely exploitable). Successful exploitation can cause denial of service via kernel panic or potentially enable privilege escalation. Patches are available through IBM Service Packs and Fix Packs as noted in the security bulletin.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM security bulletin updated with remediation guidance