IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: RCE via Off-By-One bounds check
CVE-2026-16909 Published on August 19, 2026

Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Wrap-around Error

Wrap around errors occur whenever a value is incremented past the maximum value for its type and therefore "wraps around" to a very small, negative, or undefined value.


Products Associated with CVE-2026-16909

stack.watch emails you whenever new vulnerabilities are published in IBM Aix or IBM Powervm Vios. Just hit a watch button to start following.

 
 

Affected Versions

IBM AIX: IBM PowerVM VIOS: