CVE-2026-16924
Received Received - Intake

Denial of Service in IBM AIX and PowerVM VIOS via IPsec Decapsulation

Vulnerability report for CVE-2026-16924, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: IBM Corporation

Description

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ibm aix 7.2
ibm aix 7.3
ibm powervm_vios 4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 allows a remote attacker to cause a denial of service by exploiting an improper memory offset calculation during IPsec decapsulation.

Detection Guidance

Detection requires checking for IPsec decapsulation issues in IBM AIX 7.2/7.3 or PowerVM VIOS 4.1. Monitor for crashes or memory errors during IPsec processing. Check logs for decapsulation failures or abnormal termination. Use system monitoring tools to watch for high CPU or memory usage spikes during IPsec operations.

Impact Analysis

The vulnerability could lead to system crashes or service disruptions due to a denial of service attack, potentially causing downtime for affected systems.

Compliance Impact

This vulnerability could lead to a denial of service due to improper memory offset calculation during IPsec decapsulation. While not directly impacting data confidentiality or integrity, a denial of service could disrupt systems handling sensitive data, potentially affecting compliance with standards like GDPR or HIPAA that require availability of personal or health information.

Mitigation Strategies

Apply IBM-provided patches or updates for IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 to address the improper memory offset calculation during IPsec decapsulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16924. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart