CVE-2026-16890: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Operational
For the SP/FP update, an LPAR reboot is required to complete the update.
- Operational
If using VIOS 4.1.0 or VIOS 4.1.1, perform additional post-update steps to migrate to the latest Postgres15 after applying the VIOS 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Who is able to exploit this issue?
The issue is described as exploitable by a local attacker. Remote exploitation is not indicated by the available information.
What impact could successful exploitation have?
A successful exploit could allow access to sensitive information or cause a denial of service. The reported cause is an integer overflow.
Which products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.