CVE-2026-16862: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AIX 7.2/7.3to a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
AIX 7.3to a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
AIX 7.3to a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
AIX 7.3to a version that resolves this vulnerability.Patch IJ59563 - Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Operational
After applying the AIX Service Pack (SP) or VIOS Fix Pack (FP) update, perform an LPAR reboot to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional post-update steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Which products should be included in the initial triage scope?
Include IBM AIX and IBM PowerVM VIOS systems in the initial review scope.