CVE-2026-16837: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Fixed in TL04SP2 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Fixed in TL03SP3 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Fixed in TL02SP5 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408/14/20264.1.1.30key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/20264.1.2.20key_w_apar - Operational
Perform an LPAR reboot to complete the SP/FP update after applying the AIX service pack and VIOS fix packs (unless using AIX Live Update to avoid a reboot, per the provided note).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, complete the additional post-update steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
What does an attacker need to do to trigger the denial of service?
The available information indicates that the issue is triggered by improper handling of a missing SSL client certificate. No further details are provided about the required access level, affected service, or exact request conditions.
Which IBM products should be assessed for exposure?
IBM AIX and IBM PowerVM VIOS are identified as affected software. The provided information does not specify affected versions or whether all deployments are vulnerable by default.