CVE-2026-16877: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch 4.1.2.20 - Upgrade
Upgrade
IBM AIX 7.2to a version that resolves this vulnerability.Patch SP13 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Patch SP5 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Patch SP3 - Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Patch SP2 - Compensating control
Perform an LPAR reboot after applying the AIX Service Pack / VIOS Fix Pack update to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Does exploitation require prior access?
Yes. The issue is described as exploitable by a remote authenticated attacker, so the attacker must have valid authenticated access before attempting exploitation.
Which IBM platforms are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.