CVE-2026-16855: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a heap buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2 / 7.3to a version that resolves this vulnerability.Fixed in SP13 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.2.20 - Compensating control
After applying the AIX service pack / VIOS fix pack updates, reboot the LPAR to complete the SP/FP update (LPAR reboot is required).
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is described as locally exploitable, so the attacker needs local access to an affected IBM AIX or IBM PowerVM VIOS system.
Which systems should be considered exposed?
Systems running IBM AIX or IBM PowerVM VIOS should be assessed, particularly where untrusted or less-trusted users can obtain local access.