CVE-2026-17007: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20 - Compensating control
If using nimsh secure to apply these patches, follow the special steps required because the protocol between master and client is updated to be more secure.
- Operational
After applying the AIX SP/FP update, reboot the LPAR to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1: after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Who is in scope for this issue?
The affected software listed is IBM AIX and IBM PowerVM VIOS. The issue requires local attacker access.
What could a successful attacker do?
A local attacker could obtain sensitive information or cause a denial of service through an out-of-bounds read.