CVE-2026-19442
published 2026-08-20CVE-2026-19442: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation…
PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.12%
2.0th percentile
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | 7.2.5 – 7.2.5.212 | — |
| ibm | aix | 7.3.2 – 7.3.2.5 | — |
| ibm | aix | 7.3.3 – 7.3.3.2 | — |
| ibm | aix | 7.3.4 – 7.3.4.1 | — |
| ibm | powervm_vios | — | — |
| ibm | vios | >= 4.1.0 < 4.1.0.50 | 4.1.0.50 |
| ibm | vios | >= 4.1.1.0 < 4.1.1.30 | 4.1.1.30 |
| ibm | vios | >= 4.1.2.0 < 4.1.2.20 | 4.1.2.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM AIX/PowerVM VIOS 4.1/7.2/7.3 Virtual SCSI Initiator Driver privileges management
vuldb·2026-08-21·CVSS 8.2
CVE-2026-19442 [HIGH] IBM AIX/PowerVM VIOS 4.1/7.2/7.3 Virtual SCSI Initiator Driver privileges management
A vulnerability classified as very critical was found in IBM AIX and PowerVM VIOS 7.2/7.3/4.1. Affected by this vulnerability is an unknown functionality of the component Virtual SCSI Initiator Driver. Such manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-19442. Local access is required to approach this attack. No exploit exists.
GHSA
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver.
ghsa_unreviewed·2026-08-21
CVE-2026-19442 [HIGH] CWE-822 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-20
Published