CVE-2026-16958: Vulnerabilities in IBM AIX and PowerVM VIOS
Published Aug 15, 2026
·Updated
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Affected Software
10 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
IBM VIOS>=4.1.0<4.1.0.50
IBM VIOS>=4.1.1.0<4.1.1.30
IBM VIOS>=4.1.2.0<4.1.2.20
IBM AIX>=7.2.5<=7.2.5.212
IBM AIX>=7.3.2<=7.3.2.5
IBM AIX>=7.3.3<=7.3.3.2
IBM AIX>=7.3.4<=7.3.4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar7.3.2IJ5956508/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar7.3.3IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar7.3.4IJ59563 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 fix packs/FPs, per the provided post-update instructions.
- Operational
Perform an LPAR reboot to complete the SP/FP update.
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Aug 20, 2026
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.