CVE-2026-16703: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408/14/20264.1.1.30key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/20264.1.2.20key_w_apar - Compensating control
If applying AIX/VIOS patches using nimsh secure, use the special steps required because the protocol between master and client is updated to be more secure.
- Operational
After applying the AIX SP/FP update, reboot the LPAR to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the VIOS 4.1.1.30 or 4.1.0.50 FPs.
Event History
Frequently Asked Questions
Which systems are in scope for this issue?
The issue affects IBM AIX and IBM PowerVM VIOS.
What level of access would an attacker need?
Exploitation requires local access to the affected system. A successful attacker could gain elevated privileges.