CVE-2026-17157: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.0.50 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.1.30Patch key_w_apar4.1.1 - Compensating control
For AIX/VIOS updates, ensure an LPAR reboot is performed to complete the SP/FP update (an LPAR reboot is required to complete the SP/FP update).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1: after applying the VIOS 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Which systems should be prioritized for assessment?
The affected software listed is IBM AIX and IBM PowerVM VIOS.
Does an attacker need local access to target this issue?
No. The issue is described as exploitable by a remote attacker.