Aller au contenu

Fiche vulnérabilité

CVE-2026-17138 : faille élevée IBM AIX (CVSS 8.1)

Description

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 août 2026
Dernière mise à jour
25 août 2026

Produits concernés

  • IBM AIX
  • IBM PowerVM VIOS

Correctif et mesures

A. APARS IBM has assigned the following APARs to this problem: AIX LevelAPARAvailability SPKEY7.2.5IJ5956608/14/2026SP13key_w_apar7.3.2IJ5956508/14/2026SP05key_w_apar7.3.3IJ5956408/14/2026SP03key_w_apar7.3.4IJ59563 08/14/2026SP02key_w_apar VIOS LevelAPARAvailability SPKEY4.1.0IJ5956508/14/20264.1.0.50key_w_apar4.1.1IJ5956408/14/20264.1.1.30key_w_apar4.1.2IJ5956308/14/20264.1.2.20key_w_apar B. FIXES IBM strongly recommends addressing the vulnerability now. AIX and VIOS fixes are available and can be downloaded from Fix Central: https://www.ibm.com/support/fixcentral An LPAR reboot is required to complete the SP/FP update. On AIX, Live Update can be used to avoid a reboot. IBM has assigned the following AIX Service Packs (SPs) and VIOS Fix Packs (FPs) as the remediation levels for the published vulnerabilities. AIX Level Service PackAIX 7.3 TL04SP2AIX 7.3 TL03SP3AIX 7.3 TL02SP5AIX 7.2 TL05 SP13 PowerVM VIOS LevelFix PackVIOS 4.1.2 4.1.2.20VIOS 4.1.1 4.1.1.30VIOS 4.1.0 4.1.0.50 Note: These SPs/FPs are cumulative and include fixes for all previously published AIX/VIOS security vulnerabilities. They can be applied on top of any earlier affected level of the TL . Note: To apply these patches using nimsh secure, special steps must be taken as the protocol between master and client is updated to be more secure. Please read this article: https://www.ibm.com/support/pages/node/7283157 Note: For VIOS 4.1.0 and VIOS 4.1.1, additional steps are required to migrate to the latest…

Références

Rechercher une autre vulnérabilité dans la base CVE