CVE-2026-16924
EUVD-2026-6338420.08.2026, 15:17
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 4.1.0 ≤ 𝑥 < 4.1.0.50 |
| ibm | vios | 4.1.1.0 ≤ 𝑥 < 4.1.1.30 |
| ibm | vios | 4.1.2.0 ≤ 𝑥 < 4.1.2.20 |
| ibm | aix | 7.2.5 ≤ 𝑥 ≤ 7.2.5.212 |
| ibm | aix | 7.3.2 ≤ 𝑥 ≤ 7.3.2.5 |
| ibm | aix | 7.3.3 ≤ 𝑥 ≤ 7.3.3.2 |
| ibm | aix | 7.3.4 ≤ 𝑥 ≤ 7.3.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-191 - Integer Underflow (Wrap or Wraparound)The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
- CWE-131 - Incorrect Calculation of Buffer SizeThe software does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.