CVE-2026-16706: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2 / 7.3to a version that resolves this vulnerability.Fixed in SP13Patch SPKEY7.2.5IJ5956608 - Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Fixed in SP2Patch IJ5956508 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Fixed in SP3Patch IJ5956408 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Fixed in SP5Patch IJ59563 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch 4.1.0IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch 4.1.1IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch 4.1.2IJ5956308 - Configuration
On AIX, use Live Update to avoid a reboot when applying SP/FP updates.
AIX Live Update reboot = avoided - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional required steps to migrate to the latest Postgres15.
- Operational
After applying the AIX Service Pack (SP)/VIOS Fix Pack (FP) updates, perform an LPAR reboot to complete the SP/FP update (LPAR reboot required).
Event History
Frequently Asked Questions
Which systems should be prioritized for assessment?
IBM AIX and IBM PowerVM VIOS are identified as affected software.
Does exploitation require an attacker to have local access?
The issue is described as exploitable by a remote attacker, so local access is not indicated as a requirement.