CVE-2026-17009: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL pointer dereference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2 - Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch SPKEY7.2.5 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional required steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
- Operational
Reboot the LPAR to complete the SP/FP update (an LPAR reboot is required to complete the SP/FP update).
- Operational
If using nimsh secure to apply these patches, take the special nimsh secure steps because the protocol between master and client is updated to be more secure.
Event History
Frequently Asked Questions
Who can exploit this issue?
A local attacker could exploit the NULL pointer dereference. The provided information does not indicate that remote access alone is sufficient.
What is the expected impact of successful exploitation?
Successful exploitation could cause a denial of service.
Which products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.