CVE-2026-14970: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow.
Other sources
IBM AIX NIM server process is crashing during client registration due to buffer overflow.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2 (service pack) / IBM AIX 7.3 (service pack) / IBM PowerVM VIOS 4.1 (fix pack)to a version that resolves this vulnerability.Fixed in SP13 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20 - Operational
After applying the AIX SP/FP update, perform an LPAR reboot to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Which deployments are relevant to this issue?
IBM AIX and IBM PowerVM VIOS deployments running an IBM AIX NIM server are relevant, because the affected process is the NIM server during client registration.
What observable impact could indicate exploitation or a triggering event?
The NIM server process can crash while a client is being registered. Review failures occurring in that workflow as a potential indicator.