Stack Memory Corruption in IBM AIX and PowerVM
CVE-2026-19448

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
20 August 2026

What is CVE-2026-19448?

A stack memory corruption vulnerability has been identified in the IPsec ESP decapsulation handler in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. This flaw could potentially allow an attacker to exploit the kernel stack state, leading to a system crash and resultant denial of service, which could seriously impede system availability. Users are advised to apply necessary patches as recommended by vendor advisory to ensure system integrity.

Affected Version(s)

AIX 7.2

AIX 7.3

PowerVM VIOS 4.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/).
.