Sceawere
Vulnerability Detail
CVE-2026-19653UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM AIX Page Table Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- AIX
- Attack Type
- CWE-400 Uncontrolled Resource Consumption
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper handling of memory page table configurations.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-19T18:16:36.407Z",
"pubdate": "2026-08-19T18:16:36.407Z",
"executiveSummary": "This vulnerability involves a denial of service flaw affecting IBM AIX and IBM PowerVM VIOS, specifically arising from the improper handling of memory page table configurations. A local attacker possessing standard user privileges can exploit this weakness to compromise system stability, potentially resulting in a system crash or unresponsiveness.\nThe affected products include IBM AIX 7.2 and 7.3, alongside IBM PowerVM VIOS 4.1. The primary risk implication is the disruption of critical operating system services and underlying virtualized infrastructure, leading to a loss of availability.\nExploitation of this vulnerability requires local access to the target system. The attack vector relies on the manipulation or interaction with memory management subsystems, specifically the page table configuration mechanisms, which are improperly handled by the kernel or hypervisor components. No specific exploitation requirements beyond local execution capabilities are explicitly detailed, highlighting a systemic flaw in memory bounds or state validation.",
"technicalDetails": "The root cause of the vulnerability stems from improper handling and validation of memory page table configurations within the kernel or virtualization layer of the affected operating systems and hypervisors. Memory page tables are critical structures responsible for translating virtual memory addresses to physical addresses, managed directly by the operating system kernel or the PowerVM hypervisor.\nThe vulnerable components reside within the memory management subsystems of IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS version 4.1. Because page table management requires stringent synchronization, validation, and boundary checking, any deficiency in handling specific configuration states can lead to memory corruption, null pointer dereferences, unhandled kernel traps, or deadlocks.\nThe attack flow proceeds as follows: First, a local authenticated user crafts or executes a specialized process or system call designed to interact with the memory management subsystem under specific page table configurations. Second, the user triggers the vulnerable code path responsible for processing or updating these page table entries. Third, due to the lack of proper input validation and state checking, the kernel or VIOS encounters an anomalous condition while parsing the malicious or malformed memory configuration. Finally, this anomalous condition induces a kernel panic, hypervisor crash, or severe resource exhaustion, culminating in an immediate denial of service for the logical partition or the entire managed system.\nRegarding authentication and privileges, the attack requires local access. The attacker must possess valid local credentials to execute the payload that interacts with the memory subsystem. Network exposure is indirect or non-existent for this specific local vector, as the vulnerability cannot be exploited remotely without prior local access or an existing remote execution vector into an unprivileged local shell. Post-exploitation impact is limited to availability disruption, as the primary manifestation of the flaw is system instability rather than arbitrary code execution or privilege escalation."
}