CVE-2026-16919: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX (Level SP)to a version that resolves this vulnerability.Fixed in 7.3 TL04SP2 - Upgrade
Upgrade
IBM AIX (Level SP)to a version that resolves this vulnerability.Fixed in 7.3 TL03SP3 - Upgrade
Upgrade
IBM AIX (Level SP)to a version that resolves this vulnerability.Fixed in 7.3 TL02SP5 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956608 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956508 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956408 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ59563 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956308 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
- Operational
Reboot the LPAR after completing the SP/FP update to complete the AIX SP/FP update.
Event History
Frequently Asked Questions
Which environments should be included in triage?
Review systems running IBM AIX and IBM PowerVM VIOS.