CVE-2026-16996
EUVD-2026-6363220.08.2026, 22:17
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an integer underflow.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | vios | 4.1.0 ≤ 𝑥 < 4.1.0.50 |
| ibm | vios | 4.1.1.0 ≤ 𝑥 < 4.1.1.30 |
| ibm | vios | 4.1.2.0 ≤ 𝑥 < 4.1.2.20 |
| ibm | aix | 7.2.5 ≤ 𝑥 ≤ 7.2.5.212 |
| ibm | aix | 7.3.2 ≤ 𝑥 ≤ 7.3.2.5 |
| ibm | aix | 7.3.3 ≤ 𝑥 ≤ 7.3.3.2 |
| ibm | aix | 7.3.4 ≤ 𝑥 ≤ 7.3.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
- CWE-191 - Integer Underflow (Wrap or Wraparound)The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.