CVE-2026-19446: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2/7.3to a version that resolves this vulnerability.Patch SPKEY7.2.5 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
- Compensating control
If applying these patches using nimsh secure, follow the special steps required because the protocol between master and client is updated to be more secure.
- Compensating control
On AIX, Live Update can be used to avoid a reboot.
- Operational
An LPAR reboot is required to complete the SP/FP update.
Event History
Frequently Asked Questions
What access does an attacker need to trigger the denial of service?
An attacker does not need authentication. They need network reachability to an RPC service that can receive the crafted UDP packet.
What is the operational impact if exploitation succeeds?
Successful exploitation causes complete system unavailability. Recovery requires restarting the affected LPAR.
Which products should be assessed for exposure?
Assess IBM AIX and IBM PowerVM VIOS systems, particularly LPARs with reachable RPC services exposed to networks accessible by untrusted remote users.