CVE-2026-16833: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memory due to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956608 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956508 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956408 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ59563 - Operational
For AIX SP/FP update completion, perform an LPAR reboot (required to complete the SP/FP update). Live Update can be used on AIX to avoid a reboot.
- Operational
For VIOS 4.1.0.50 and VIOS 4.1.1.30, perform additional steps to migrate to the latest Postgres15 after applying the respective FP.
Event History
Frequently Asked Questions
Which IBM environments should be assessed for exposure?
The affected software list identifies IBM AIX and IBM PowerVM VIOS.
Does the available information indicate that an attacker needs local access?
No. The issue is described as exploitable by a remote attacker.
Are fixed versions or interim mitigations provided in the available record?
No fixed versions or mitigation steps are stated in the supplied information.