CVE-2026-19442
Received Received - Intake

Pointer Validation Flaw in IBM AIX vSCSI Initiator Driver

Vulnerability report for CVE-2026-19442, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: IBM Corporation

Description

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ibm aix 7.2
ibm aix 7.3
ibm powervm_vios 4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a pointer validation flaw in the AIX Virtual SCSI (vSCSI) initiator driver on IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. It may allow attackers to cause a denial of service, escalate privileges, or fully compromise the client LPAR kernel.

Detection Guidance

Detection requires checking for vulnerable IBM AIX or PowerVM VIOS versions. Use uname -a to verify AIX version and ioslevel for PowerVM VIOS. Monitor for kernel crashes or privilege escalation attempts in logs.

Impact Analysis

If exploited, this flaw could lead to system crashes, unauthorized access to sensitive data, or complete control over the affected system by attackers.

Compliance Impact

The vulnerability may lead to unauthorized access or privilege escalation in IBM AIX and PowerVM VIOS systems, which could compromise data confidentiality and integrity. This could potentially violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) if exploited.

Mitigation Strategies

Apply IBM-provided patches for AIX 7.2/7.3 and PowerVM VIOS 4.1. Restrict access to vSCSI initiator driver. Monitor for suspicious activity and isolate affected systems if exploited.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19442. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart