CVE-2026-17124: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AIX 7.2 TL05to a version that resolves this vulnerability.Fixed in SP13Patch SPKEY7.2.5 - Upgrade
Upgrade
AIX 7.3 TL04to a version that resolves this vulnerability.Fixed in SP2 - Upgrade
Upgrade
AIX 7.3 TL03to a version that resolves this vulnerability.Fixed in SP3 - Upgrade
Upgrade
AIX 7.3 TL02to a version that resolves this vulnerability.Fixed in SP5 - Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar - Compensating control
If applying VIOS/AIX patches using nimsh secure, follow the additional steps required because the protocol between master and client is updated to be more secure (per the article).
- Operational
Reboot the LPAR to complete the SP/FP update (AIX Live Update can be used to avoid a reboot, per the article).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.
Event History
Frequently Asked Questions
Does exploitation require remote network access?
The issue is described as allowing a local attacker to execute arbitrary code, so the attacker needs local access to the affected system.
Which IBM products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.