CVE-2026-16951: Buffer Overflow
Published Aug 15, 2026
·Updated
AIX could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
Affected Software
3 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
A local attacker who is already authenticated to an affected IBM AIX or IBM PowerVM VIOS system could exploit it.
2
What level of access does an attacker need?
The attacker needs local authenticated access; the provided information does not indicate that remote unauthenticated exploitation is possible.
3
What could successful exploitation allow?
Successful exploitation could allow execution of arbitrary code on the affected system.