CVE-2026-16886: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch 4.1.0IJ5956508/14/20264.1.0.50key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch 4.1.1IJ5956408/14/20264.1.1.30key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch 4.1.2IJ5956308/14/20264.1.2.20key_w_apar - Configuration
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
IBM PowerVM VIOS Postgres 15 migration step = required after applying VIOS 4.1.0.50 or 4.1.1.30 - Operational
After applying the AIX SP/FP update (SPs/FPs listed in the remediation levels), reboot the LPAR to complete the SP/FP update.
Event History
Frequently Asked Questions
What impact can an attacker achieve?
A remote attacker could cause a denial of service through an out-of-bounds write.
Which IBM products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.