CVE-2026-16851: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a use-after-free.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508/14/20264.1.0.50key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408/14/20264.1.1.30key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308/14/20264.1.2.20key_w_apar - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956608/14/2026SP13key_w_apar - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956408/14/2026SP03key_w_apar - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ59563 - Operational
Perform an LPAR reboot to complete the SP/FP update (reboot is required to complete the AIX service pack / VIOS fix pack update). For VIOS 4.1.0 and VIOS 4.1.1, follow additional post-update steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Which systems should be investigated for exposure?
Investigate systems running IBM AIX or IBM PowerVM VIOS. The provided data does not identify affected or fixed versions.
What attacker access or prerequisites are specified?
The issue is described as remotely exploitable. The provided data does not state whether authentication, a particular service, or any additional configuration is required.
Are temporary mitigations available if patching cannot happen immediately?
No workaround or mitigation is provided in the supplied data.