CVE-2026-16911: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Compensating control
Perform an LPAR reboot to complete the SP/FP update (a reboot is required to complete the SP/FP update).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, migrate to the latest Postgres15 using the additional post-update steps referenced in the IBM post-update instructions.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remote and authenticated. The available information does not identify the specific service, interface, or privileges required after authentication.
Which systems should be considered potentially exposed?
IBM AIX and IBM PowerVM VIOS are listed as affected software. Systems running those products should be reviewed against the IBM advisory, particularly where remote authenticated access is available.