Buffer Overflow in IBM AIX and PowerVM Affecting Client Registration
CVE-2026-14970

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-14970?

A buffer overflow vulnerability has been identified in IBM AIX versions 7.2 and 7.3, along with IBM PowerVM VIOS version 4.1. This flaw causes the NIM server process to crash during client registration, potentially leading to denial of service and disruption of services in environments reliant on these systems. Immediate attention to patching and mitigating this issue is recommended to safeguard operational integrity.

Affected Version(s)

AIX 7.2

AIX 7.3

PowerVM VIOS 4.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/).
.