CVE-2026-17120: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1to a version that resolves this vulnerability.Fixed in 4.1.2.20 - Configuration
After applying the VIOS 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15 (per the VIOS post-update instructions for 4.1.0.50 and 4.1.1.30).
IBM PowerVM VIOS 4.1.0 and VIOS 4.1.1 Postgres15 migration = required - Operational
Perform an LPAR reboot to complete the SP/FP update (AIX Service Pack / VIOS Fix Pack remediation requires an LPAR reboot).
Event History
Frequently Asked Questions
What impact can an attacker achieve?
A remote attacker could cause a denial of service through a buffer overflow.
Which products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.