CVE-2026-16951: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar - Operational
Reboot the LPAR required to complete the SP/FP update.
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
A local attacker who is already authenticated to an affected IBM AIX or IBM PowerVM VIOS system could exploit it.
What level of access does an attacker need?
The attacker needs local authenticated access; the provided information does not indicate that remote unauthenticated exploitation is possible.
What could successful exploitation allow?
Successful exploitation could allow execution of arbitrary code on the affected system.