CVE-2026-17145: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2to a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Patch IJ59563 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Configuration
For VIOS 4.1.0 and VIOS 4.1.1, perform the required migration to the latest Postgres15 after applying the specified VIOS FPs.
IBM PowerVM VIOS Postgres15 migration after applying VIOS fixes = Migrate to the latest Postgres15 after applying VIOS 4.1.1.30 or VIOS 4.1.0.50 FPs (additional steps required). - Compensating control
If using AIX nimsh secure to apply these patches, take the special steps described in the referenced guidance because the protocol between master and client is updated to be more secure.
- Compensating control
On AIX, use Live Update to avoid a reboot where possible (otherwise perform the required LPAR reboot to complete the SP/FP update).
- Operational
Reboot the LPAR to complete the SP/FP update (required after applying the AIX/VIOS SP/FP remediation levels).