CVE-2026-17118: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408/14/20264.1.1.30key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/20264.1.2.20key_w_apar - Operational
An LPAR reboot is required to complete the SP/FP update (AIX/VIOS).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Which IBM products should be included in the exposure assessment?
Assess IBM AIX and IBM PowerVM VIOS systems.
Is local access required for exploitation?
The vulnerability is described as remotely exploitable. The available information does not specify authentication requirements, the affected network service, or other prerequisites.
Can affected releases be identified from the available record?
No affected or fixed version information is provided. The IBM support reference should be consulted to determine whether deployed releases are affected and whether updates are available.