IBMCVE-2026-19442
IBM AIX: denial of service
High8.2CVE-2026-19442 · Published Aug 20, 2026 · updated Aug 25, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| AIX Product | <= 7.2 | No fix yet |
| <= 7.3 | No fix yet | |
| PowerVM VIOS Product | <= 4.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-822
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 20 | IBM AIX: resource exhaustion | High7.5 | No fix yet |
| Aug 20 | IBM AIX: memory corruption | Medium6.5 | No fix yet |
| Aug 20 | IBM AIX: improper privilege management | High8.8 | No fix yet |
| Aug 20 | IBM AIX: memory corruption | Medium6.7 | No fix yet |
| Aug 20 | IBM AIX: denial of service | Medium5.4 | No fix yet |
| Aug 20 | IBM AIX: remote code execution | High8.8 | No fix yet |