CVE-2026-16909
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-128
- Published
- 2026-08-19
- Last modified
- 2026-08-21
Affected products
- IBM AIX
- IBM AIX
- IBM PowerVM VIOS
Weakness type
Related vulnerabilities
- CVE-2026-54905 — concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
- CVE-2024-23981 — Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and...
- CVE-2022-35258 — An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect...