CVE-2026-19783
published 2026-08-20CVE-2026-19783: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.6th percentile
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | 7.2.5 – 7.2.5.212 | — |
| ibm | aix | 7.3.2 – 7.3.2.5 | — |
| ibm | aix | 7.3.3 – 7.3.3.2 | — |
| ibm | aix | 7.3.4 – 7.3.4.1 | — |
| ibm | powervm_vios | — | — |
| ibm | vios | >= 4.1.0 < 4.1.0.50 | 4.1.0.50 |
| ibm | vios | >= 4.1.1.0 < 4.1.1.30 | 4.1.1.30 |
| ibm | vios | >= 4.1.2.0 < 4.1.2.20 | 4.1.2.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM AIX/PowerVM VIOS Directory buffer overflow
vuldb·2026-08-21·CVSS 6.7
CVE-2026-19783 [MEDIUM] IBM AIX/PowerVM VIOS Directory buffer overflow
A vulnerability has been found in IBM AIX and PowerVM VIOS and classified as very critical. This vulnerability affects unknown code of the component Directory. The manipulation leads to buffer overflow.
This vulnerability is referenced as CVE-2026-19783. The attack can only be performed from a local environment. No exploit is available.
GHSA
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation.
ghsa_unreviewed·2026-08-21
CVE-2026-19783 [MEDIUM] CWE-787 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-20
Published