CVE-2026-16819: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-of-check time-of-use race condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/2026 - Operational
An LPAR reboot is required to complete the SP/FP update (post-update instructions referenced for AIX/VIOS include the need to reboot an LPAR).
Event History
Frequently Asked Questions
Who can exploit this issue?
A local attacker could exploit the race condition. The provided information does not indicate that remote access alone is sufficient.
What impacts are described if exploitation succeeds?
Successful exploitation could cause a denial of service and compromise data integrity.
Which products are identified as affected?
The issue is identified for IBM AIX and IBM PowerVM VIOS.