CVE-2026-19448: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch SPKEY7.2.5 - Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Patch IJ5956308 - Operational
Reboot the LPAR to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.