CVE-2026-16841: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, after applying the listed FPs (4.1.0.50 or 4.1.1.30), migrate to the latest Postgres15 per the post-update instructions (additional steps are required).
- Operational
After applying the AIX Service Pack / VIOS Fix Pack updates, reboot the LPAR to complete the SP/FP update (an LPAR reboot is required). Live Update on AIX can be used to avoid a reboot.
Event History
Frequently Asked Questions
Does the affected scope include IBM virtual I/O environments?
Yes. The listed software includes IBM PowerVM VIOS, in addition to IBM AIX.