CVE-2026-19442: IBM Aix

High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.

Affected products

  • IBM Aix: from 7.2.5, up to and including 7.2.5.212; from 7.3.2, up to and including 7.3.2.5; from 7.3.3, up to and including 7.3.3.2; from 7.3.4, up to and including 7.3.4.1
  • IBM Vios: from 4.1.0, before 4.1.0.50 (fixed in 4.1.0.50); from 4.1.1.0, before 4.1.1.30 (fixed in 4.1.1.30); from 4.1.2.0, before 4.1.2.20 (fixed in 4.1.2.20)

Published 2026-08-20. Last modified 2026-08-25.