CVE-2026-16838: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch SPKEY7.2.5I - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20 - Operational
Reboot the LPAR to complete the SP/FP update (LPAR reboot is required to complete the SP/FP update).
- Operational
For VIOS 4.1.0.50 and VIOS 4.1.1.30: perform additional steps to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.
Event History
Frequently Asked Questions
Is IBM PowerVM VIOS affected as well as IBM AIX?
Yes. The affected software list includes both IBM AIX and IBM PowerVM VIOS.
Does exploitation require local access?
The issue is described as exploitable by a local attacker. The provided information does not identify a remote exploitation path.