CVE-2026-16997: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper privilege management.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20 - Compensating control
If applying VIOS 4.1.0.50 or VIOS 4.1.1.30, perform the additional required steps to migrate to the latest Postgres15 after applying the VIOS FPs.
- Operational
Reboot the LPAR after applying the AIX Service Pack (SP) / FP update to complete the SP/FP update.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue requires local attacker access.
Which products should be assessed for exposure?
Assess IBM AIX and IBM PowerVM VIOS systems.