Out-of-Bounds Write Vulnerability in IBM AIX and PowerVM Products
CVE-2026-18842
8.4HIGH
What is CVE-2026-18842?
An out-of-bounds write vulnerability exists in IBM AIX versions 7.2 and 7.3, as well as the IBM PowerVM VIOS 4.1. This flaw potentially allows a local attacker to gain elevated privileges by manipulating memory allocations improperly, leading to unauthorized access and control over system resources. Organizations using these products should apply the necessary patches to safeguard against potential exploitation.
Affected Version(s)
AIX 7.2
AIX 7.3
PowerVM VIOS 4.1
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/).