CVE-2026-16924CWE-131CWE-191

CVE-2026-16924

High · published August 20, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
23.8
In the wild
Unconfirmed
What it is

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00314 · 23.8th percentile
Weaknesses
CWE-131 · Incorrect Calculation of Buffer Size; CWE-191 · Integer Underflow (Wrap or Wraparound)
Published
2026-08-20T19:17Z
Affected products (7)
ProductVersionsFixed in
ibm/vios≥ 4.1.0, < 4.1.0.504.1.0.50
ibm/vios≥ 4.1.1.0, < 4.1.1.304.1.1.30
ibm/vios≥ 4.1.2.0, < 4.1.2.204.1.2.20
ibm/aix≥ 7.2.5, ≤ 7.2.5.212
ibm/aix≥ 7.3.2, ≤ 7.3.2.5
ibm/aix≥ 7.3.3, ≤ 7.3.3.2
ibm/aix≥ 7.3.4, ≤ 7.3.4.1
References (1)
EPSS history
Timeline
  • 20 AUG 14:37Z
    Vulnerabilities in IBM AIX and PowerVM VIOS
    cvelistv5