Denial of Service Vulnerability in IBM AIX and PowerVM Products
CVE-2026-18828
5.4MEDIUM
What is CVE-2026-18828?
IBM AIX versions 7.2 and 7.3, along with IBM PowerVM VIOS 4.1, are susceptible to a stack-based buffer overflow that enables remote attackers to execute denial of service attacks. By sending crafted requests to vulnerable components, attackers can exploit this weakness, potentially disrupting service and affecting system availability. Patching is imperative to mitigate these risks and ensure the integrity of the affected systems.
Affected Version(s)
AIX 7.2
AIX 7.3
PowerVM VIOS 4.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/).