CVE-2026-19442
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.12%
- CWE
- CWE-822
- Published
- 2026-08-20
- Last modified
- 2026-08-22
Affected products
- IBM AIX
- IBM AIX
- IBM PowerVM VIOS
Weakness type
Related vulnerabilities
- CVE-2026-83498 — Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
- CVE-2026-83939 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- CVE-2026-78451 — Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
- CVE-2026-78444 — Microsoft Failover Cluster Remote Code Execution Vulnerability
- CVE-2026-72938 — Microsoft Office PowerPoint Information Disclosure Vulnerability
- CVE-2026-72956 — Microsoft Office PowerPoint Information Disclosure Vulnerability
- CVE-2026-69874 — Windows ALPC Elevation of Privilege Vulnerability
- CVE-2026-69900 — Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability