CVE-2026-16894: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar7.3.2IJ5956508/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar7.3.3IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar7.3.4IJ59563 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 fix packs, perform the additional steps required to migrate to the latest Postgres15.
- Operational
Reboot the LPAR after applying the AIX Service Pack (SP) / VIOS Fix Pack (FP) update to complete the update.
Event History
Frequently Asked Questions
Does exploitation require local access to the affected system?
No. The issue could allow a remote attacker to execute arbitrary code.
Which IBM products are identified as affected?
IBM AIX and IBM PowerVM VIOS are identified as affected.