CVE-2026-16945: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508/14/2026 - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408/14/2026 - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308/14/2026 - Operational
An LPAR reboot is required to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, additional steps are required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.
Event History
Frequently Asked Questions
Does exploitation require access to the affected system?
Yes. The issue is described as requiring a local attacker, so exposure is limited to attackers who can obtain local access to an affected system.
Which IBM products should be included in impact assessment?
Assess IBM AIX and IBM PowerVM VIOS systems, as both are listed as affected software.