IBM has released security updates for AIX 7.2, AIX 7.3, And PowerVM VIOS 4.1.
The affected products are AIX 7.2, AIX 7.3, And PowerVM VIOS 4.1.
These updates address several vulnerabilities in the IBM Java SDK (IBM Java Development Kit). These include remote denial of service, information disclosure, input validation errors, remote data tampering, local privilege escalation, arbitrary code execution, local security feature bypass, application crashes, remote information disclosure and data tampering, and denial of service.
Various vulnerabilities have also been fixed in IBM AIX and PowerVM VIOS. These include buffer overflows, out-of-bounds reads and writes, uninitialized stack pointers, TOCTOU (time-of-check-time-of-use) race conditions, improper authentication, improper certificate validation, command injection, format string vulnerabilities, integer overflows and underflows, symbolic link processing errors, improper application of RBAC authentication roles, environment variable processing errors, reuse of freed memory, and path traversal.
The impact of these vulnerabilities ranges from remote or local threat actors causing a denial of service, exposing sensitive information and kernel memory, manipulating network traffic and DNS settings, accessing NFS-exposed file systems, performing arbitrary command execution and arbitrary code execution, gaining root privileges and privilege escalation, or overwrite arbitrary files.
Separate vulnerabilities in the NIMESIS registration service and NIM have also been fixed. A path traversal vulnerability in the NIMESIS registration service enables arbitrary file overwriting, while NIM’s improper TLS certificate validation could allow unauthorized access. This also includes vulnerabilities in NIM related to security policy bypass and OS command injection.
Patches were provided in the August 21, 2026, update. The fixed versions provided are AIX 7.2.5 SP13, AIX 7.3.2 SP05, AIX 7.3.3 SP03, AIX 7.3.4 SP02, and PowerVM VIOS 4.1.0, 4.1.0.50, 4.1.1, 4.1.1.30, And 4.1.2, 4.1.2.20.