CVE-2026-16928: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar7.3.2IJ5956508/14/2026SP05key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar7.3.3IJ5956408/14/2026SP03key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/2026 - Operational
After applying the AIX Service Pack (SP) / PowerVM VIOS Fix Pack (FP) update, reboot the LPAR is required to complete the SP/FP update.
- Operational
For VIOS 4.1.0.50 and 4.1.1.30 remediation, perform the additional required steps to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.
Event History
Frequently Asked Questions
Which systems should be assessed for exposure?
Assess systems running IBM AIX and IBM PowerVM VIOS.