CVE-2026-17171

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.
References
Link Resource
https://www.ibm.com/support/pages/node/7283858 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-20 22:17

Updated : 2026-08-25 18:31


NVD link : CVE-2026-17171

Mitre link : CVE-2026-17171

CVE.ORG link : CVE-2026-17171


JSON object : View

Products Affected

ibm

  • aix
  • vios
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')