Description
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.
Published: 2026-08-20
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 can allow a remote attacker to compromise the confidentiality and integrity of the system due to an out‑of‑bounds write. The vulnerability is classified as CWE‑787 and is rated with a CVSS score of 7.7, indicating a high potential for damage. It could permit the attacker to read or modify protected data on the affected systems.

Affected Systems

Affected vendors and products include IBM AIX versions 7.2 and 7.3 (specifically the 7.3 TL 04 SP 2, 7.3 TL 03 SP 3, 7.3 TL 02 SP 5, 7.2 TL 05 SP 13) and IBM PowerVM VIOS 4.1, with the recommended remediation levels being VIOS 4.1.2 4.1.2.20, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.0 4.1.0.50. The advisory notes that these service packs and fix packs are cumulative and include all prior fixes, and they can be applied to any earlier affected major release.

Risk and Exploitability

The high CVSS score of 7.7 reflects a significant risk, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Attackers with network access to the AIX or VIOS environment could use the flaw to execute an out‑of‑bounds write, thereby compromising confidentiality and integrity. No publicly available exploit code is mentioned, but the nature of the weakness indicates that a crafted input could trigger the vulnerability. Immediate patching is recommended to mitigate this risk.

Generated by OpenCVE AI on August 20, 2026 at 23:50 UTC.

Remediation

Vendor Solution

A.  APARS IBM has assigned the following APARs to this problem: AIX LevelAPARAvailability  SPKEY7.2.5IJ5956608/14/2026SP13key_w_apar7.3.2IJ5956508/14/2026SP05key_w_apar7.3.3IJ5956408/14/2026SP03key_w_apar7.3.4IJ59563 08/14/2026SP02key_w_apar VIOS LevelAPARAvailability SPKEY4.1.0IJ5956508/14/20264.1.0.50key_w_apar4.1.1IJ5956408/14/20264.1.1.30key_w_apar4.1.2IJ5956308/14/20264.1.2.20key_w_apar B.  FIXES IBM strongly recommends addressing the vulnerability now.  AIX and VIOS fixes are available and can be downloaded from Fix Central: https://www.ibm.com/support/fixcentral  An LPAR reboot is required to complete the SP/FP update. On AIX, Live Update can be used to avoid a reboot.  IBM has assigned the following AIX Service Packs (SPs) and VIOS Fix Packs (FPs) as the remediation levels for the published vulnerabilities. AIX Level Service PackAIX 7.3 TL04SP2AIX 7.3 TL03SP3AIX 7.3 TL02SP5AIX 7.2 TL05 SP13 PowerVM VIOS LevelFix PackVIOS 4.1.2 4.1.2.20VIOS 4.1.1 4.1.1.30VIOS 4.1.0  4.1.0.50 Note: These SPs/FPs are cumulative and include fixes for all previously published AIX/VIOS security vulnerabilities. They can be applied on top of any earlier affected level of the TL . Note: To apply these patches using nimsh secure, special steps must be taken as the protocol between master and client is updated to be more secure. Please read this article: https://www.ibm.com/support/pages/node/7283157 Note: For VIOS 4.1.0 and VIOS 4.1.1, additional steps are required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs above. Instructions to do that can be found here:                             4.1.0.50 post-update instructions: https://www.ibm.com/support/pages/node/7283819           4.1.1.30 post-update instructions: https://www.ibm.com/support/pages/node/7283823


OpenCVE Recommended Actions

  • Download and install the AIX Service Pack or VIOS Fix Pack updates listed in the advisory from IBM Fix Central; these cumulative patches contain the fix for this vulnerability.
  • For AIX, apply the update using Live Update when possible to avoid a reboot; if Live Update is not an option, reboot the system after the update to complete installation.
  • For VIOS, after applying the FP, follow IBM's post‑update instructions to migrate to PostgreSQL 15 per the links provided in the advisory.

Generated by OpenCVE AI on August 20, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm vios
CPEs cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
Vendors & Products Ibm vios

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.
Title Vulnerabilities in IBM AIX and PowerVM VIOS
First Time appeared Ibm
Ibm aix
Ibm powervm Vios
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:aix:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aix:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aix:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aix:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_vios:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_vios:4.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aix
Ibm powervm Vios
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-25T03:55:59.920Z

Reserved: 2026-07-24T09:36:53.010Z

Link: CVE-2026-17003

cve-icon Vulnrichment

Updated: 2026-08-21T16:00:13.642Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:10.983

Modified: 2026-08-25T13:58:13.843

Link: CVE-2026-17003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T00:00:05Z

Weaknesses