CVE-2026-16903: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2 - Upgrade
Upgrade
IBM AIX 7.2to a version that resolves this vulnerability.Fixed in SP13Patch IJ5956608 - Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Fixed in SP2Patch IJ5956508 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Fixed in SP3Patch IJ5956408 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Fixed in SP5Patch IJ59563 - Compensating control
If updating via nimsh secure, take the special steps mentioned in the article because the protocol between the nimsh master and client is updated to be more secure.
- Compensating control
For AIX, use Live Update to avoid a reboot when applying the SP/FP remediation levels.
- Operational
An LPAR reboot is required to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, perform additional steps to migrate to the latest Postgres15.