CVE-2026-19446
Received Received - Intake

Remote Unauthenticated UDP Packet DoS in IBM AIX and PowerVM VIOS

Vulnerability report for CVE-2026-19446, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: IBM Corporation

Description

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ibm aix 7.2
ibm aix 7.3
ibm powervm_vios 4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a remote attacker to send a specially crafted UDP packet to a reachable RPC service on IBM AIX 7.2, 7.3, or IBM PowerVM VIOS 4.1. The attack causes the system to become completely unavailable, requiring a restart of the logical partition (LPAR) to recover.

Detection Guidance

Detecting this vulnerability requires monitoring for crafted UDP packets sent to RPC services. Check network traffic for unusual UDP packets targeting RPC ports (e.g., 111 for portmapper). Use tcpdump or Wireshark to capture and analyze UDP traffic on these ports. Ensure RPC services are not exposed to untrusted networks.

Impact Analysis

If you use IBM AIX 7.2, 7.3, or IBM PowerVM VIOS 4.1, an attacker could exploit this to crash your system remotely without authentication. This results in downtime and requires manual intervention to restart the system.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing system unavailability, which may lead to disruptions in data processing or access to sensitive information. Unavailability of systems could result in violations of availability requirements under these regulations.

Mitigation Strategies

Apply IBM-provided patches or updates for AIX 7.2, 7.3, and PowerVM VIOS 4.1. Block or restrict access to RPC services via network firewalls until patches are applied. Monitor IBM security advisories for specific mitigation instructions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19446. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart