CVE-2026-16924: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2/7.3to a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956308 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Operational
Reboot the LPAR to complete the SP/FP update (required to complete the service pack/fix pack update).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
The issue is described as remotely exploitable during IPsec decapsulation, so an attacker would need to send traffic that reaches an affected system's IPsec decapsulation processing.
Which environments should be prioritized for review?
Review IBM AIX systems and IBM PowerVM VIOS environments that process IPsec traffic, since both products are listed as affected.
What is the known impact?
The reported impact is denial of service caused by an improper memory-offset calculation during IPsec decapsulation.