CVE-2026-16922: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AIX 7.3 TL04to a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
AIX 7.3 TL03to a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
AIX 7.3 TL02to a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
AIX 7.2 TL05to a version that resolves this vulnerability.Patch IJ59563 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Operational
An LPAR reboot is required to complete the SP/FP update (including after applying the AIX Service Packs and PowerVM VIOS Fix Packs). On AIX, Live Update can be used to avoid a reboot.
Event History
Frequently Asked Questions
Which products should be included in the impact assessment?
The affected software listed is IBM AIX and IBM PowerVM VIOS.