CVE-2026-16845: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar - Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch key_w_apar - Compensating control
When applying AIX/VIOS patches using nimsh secure, take the special steps because the protocol between master and client is updated to be more secure.
- Compensating control
On AIX, you can use Live Update to avoid a reboot when applying the SP/FP update.
- Operational
After applying the AIX Service Pack/VIOS Fix Pack updates, reboot the LPAR to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1: after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Which IBM products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.
Does exploitation require local access to the affected system?
No. The issue is described as exploitable by a remote attacker.