CVE-2026-16883: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20 - Compensating control
Migrate VIOS 4.1.0/4.1.1 to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs (additional steps are required per the referenced VIOS post-update instructions).
- Operational
Perform an LPAR reboot after completing the SP/FP update to complete the AIX/VIOS service pack/fix pack update.
Event History
Frequently Asked Questions
Which IBM products should be reviewed for exposure?
The affected software list includes IBM AIX and IBM PowerVM VIOS.
Does the available information identify fixed versions or a workaround?
No fixed versions, configuration mitigations, or workarounds are provided in the available data.