CVE-2026-16891: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20 - Compensating control
If applying AIX/VIOS patches using nimsh secure, follow the special nimsh secure steps because the protocol between master and client is updated to be more secure (as stated in the provided material).
- Operational
For AIX SP/FP updates, reboot the LPAR to complete the SP/FP update (explicitly required in the provided post-update instructions).
- Operational
For VIOS 4.1.0.50 and VIOS 4.1.1.30, perform the additional steps required to migrate to the latest Postgres15 after applying the specified 4.1.1.30 or 4.1.0.50 FPs (per the provided note and post-update instructions).
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local access to an affected IBM AIX or IBM PowerVM VIOS system. The available information does not indicate that it can be exploited remotely.
What is the potential impact?
A local attacker may obtain sensitive information through an out-of-bounds read.