CVE-2026-19783: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408/14/20264.1.1.30 - Upgrade
Upgrade
PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/20264.1.2.20 - Operational
After updating the AIX Service Pack (SP) / PowerVM VIOS Fix Pack (FP), perform an LPAR reboot to complete the SP/FP update. (Note: On AIX, Live Update can be used to avoid a reboot.)
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional required steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to an affected IBM AIX or IBM PowerVM VIOS system and must be able to cause the system to read a crafted filesystem image.
What could successful exploitation cause?
The crafted image can trigger an out-of-bounds write on the kernel stack while directories are read. This can crash the system and may potentially allow privilege escalation.