CVE-2026-14970: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308/14/2026 - Compensating control
On AIX, use Live Update to avoid a reboot when completing the SP/FP update.
- Operational
Reboot the LPAR is required to complete the SP/FP update (AIX/VIOS LPAR reboot required).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps to migrate to the latest Postgres15 after applying the VIOS 4.1.1.30 or 4.1.0.50 FPs.
- Operational
If applying AIX/VIOS patches using nimsh secure, follow the special steps required because the protocol between master and client is updated to be more secure.
Event History
Frequently Asked Questions
Which deployments are relevant to this issue?
IBM AIX and IBM PowerVM VIOS deployments running an IBM AIX NIM server are relevant, because the affected process is the NIM server during client registration.
What observable impact could indicate exploitation or a triggering event?
The NIM server process can crash while a client is being registered. Review failures occurring in that workflow as a potential indicator.