CVE-2026-17160

9.8

IBM · AIX

IBM AIX and PowerVM VIOS are affected by an integer overflow vulnerability during size computation, which allows remote, unauthenticated attackers to execute arbitrary code.

Executive summary

An integer overflow vulnerability in IBM AIX and PowerVM VIOS allows remote, unauthenticated attackers to trigger memory corruption and execute arbitrary code.

Vulnerability

This vulnerability, classified as CWE-190, occurs due to an integer overflow during size computation. This allows a remote attacker to trigger a heap or stack corruption, leading to arbitrary code execution.

Business impact

The ability for a remote attacker to execute arbitrary code without authentication poses a catastrophic risk. Potential outcomes include total system compromise, exfiltration of proprietary data, and significant operational downtime. The CVSS score of 9.8 highlights the severity of this memory safety issue.

Remediation

Immediate Action: Install the specific APAR fixes provided by IBM, such as APAR IJ59564 for AIX 7.3.3 or IJ59565 for VIOS 4.1.0, to address the integer overflow logic.

Proactive Monitoring: Watch for system crashes, unexpected restarts, or anomalous memory usage patterns that could indicate a failed or successful exploitation attempt.

Compensating Controls: Deploy WAF or network-level inspection rules that can detect and drop malformed packets designed to trigger integer overflows in system services.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations must treat this as a high-priority remediation task. The potential for unauthenticated remote code execution necessitates the immediate application of the vendor patches to ensure system stability and security against memory corruption attacks.

More IBM CVEs