CVE-2026-16838: Race Condition
Published Aug 15, 2026
·Updated
AIX could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
Affected Software
3 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Is IBM PowerVM VIOS affected as well as IBM AIX?
Yes. The affected software list includes both IBM AIX and IBM PowerVM VIOS.
2
Does exploitation require local access?
The issue is described as exploitable by a local attacker. The provided information does not identify a remote exploitation path.