CVE-2026-19442CWE-822

CVE-2026-19442

High · published August 21, 2026

CVSS v3.1
8.2
EPSS
0%
Percentile
2.0
In the wild
Unconfirmed
What it is

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.

The record
Technical detail
CVSS v3.1
8.2 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00120 · 2.0th percentile
Weakness
CWE-822 · Untrusted Pointer Dereference
Published
2026-08-21T02:17Z
Affected products (7)
ProductVersionsFixed in
ibm/vios≥ 4.1.0, < 4.1.0.504.1.0.50
ibm/vios≥ 4.1.1.0, < 4.1.1.304.1.1.30
ibm/vios≥ 4.1.2.0, < 4.1.2.204.1.2.20
ibm/aix≥ 7.2.5, ≤ 7.2.5.212
ibm/aix≥ 7.3.2, ≤ 7.3.2.5
ibm/aix≥ 7.3.3, ≤ 7.3.3.2
ibm/aix≥ 7.3.4, ≤ 7.3.4.1
References (1)
EPSS history
Timeline
  • 20 AUG 22:03Z
    Vulnerabilities in IBM AIX and PowerVM VIOS
    cvelistv5