CVE-2026-16927: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2/7.3 (SP remediation)to a version that resolves this vulnerability.Fixed in SP13 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ595650 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ595640 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ595630 - Compensating control
Perform an LPAR reboot to complete the SP/FP update (explicitly required to complete the SP/FP update). If applying on AIX, Live Update can be used to avoid a reboot.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 fix packs above, perform the additional required steps to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running IBM AIX or IBM PowerVM VIOS are identified as affected. Exploitation requires local attacker access.
What level of access could an attacker obtain?
A successful attacker could gain root privileges through the race condition.
What is known about exploit prerequisites?
The available information identifies this as a local privilege-escalation issue caused by a time-of-check to time-of-use race condition. No further prerequisites, affected versions, or configuration details are provided.