CVE-2026-19442: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Fixed in AIX 7.3 TL04SP2 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Fixed in AIX 7.3 TL03SP3 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Fixed in AIX 7.3 TL02SP5 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/2026 - Operational
Reboot the LPAR required to complete the SP/FP update.
Event History
Frequently Asked Questions
Which systems are in scope for this issue?
The listed affected products are IBM AIX and IBM PowerVM VIOS. The flaw is in the AIX Virtual SCSI initiator driver and affects the client LPAR kernel.