CVE-2026-16821: Vulnerabilities in IBM AIX and PowerVM VIOS
AIX could allow a local attacker to gain elevated privileges due to a format string vulnerability.
Other sources
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508/14/2026 - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408/14/2026 - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308/14/2026 - Upgrade
Upgrade
AIX 7.2to a version that resolves this vulnerability.Patch IJ5956608/14/2026 - Upgrade
Upgrade
AIX 7.3 TL04to a version that resolves this vulnerability.Patch IJ5956508/14/2026 - Upgrade
Upgrade
AIX 7.3 TL03to a version that resolves this vulnerability.Patch IJ5956408/14/2026 - Upgrade
Upgrade
AIX 7.3 TL02to a version that resolves this vulnerability.Patch IJ5956308/14/2026 - Compensating control
If applying the VIOS/AIX fixes using nimsh secure, take the additional required steps because the protocol between the master and client is updated to be more secure.
- Operational
Reboot the LPAR to complete the SP/FP update (an LPAR reboot is required to complete the SP/FP update). On AIX, Live Update can be used to avoid a reboot.
Event History
Frequently Asked Questions
What level of access does an attacker need?
The issue is described as exploitable by a local attacker. The provided information does not describe a remote attack path.
Which systems should be reviewed for exposure?
Review systems running IBM AIX or IBM PowerVM VIOS, particularly where untrusted users or processes can obtain local access.