CVE-2026-16690: Vulnerabilities in IBM AIX and PowerVM VIOS
AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
Other sources
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.0.50 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.1.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.2.20 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956508 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956408 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956308 - Operational
For AIX SP/FP updates, perform an LPAR reboot to complete the SP/FP update.
- Operational
For PowerVM VIOS 4.1.0.50 and 4.1.1.30 remediation, follow the additional steps required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 fix packs.