CVE-2026-17159: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Compensating control
When applying AIX/VIOS patches using nimsh secure, follow the special steps mentioned in the article because the protocol between master and client is updated to be more secure.
- Operational
Reboot the LPAR is required to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, complete the additional steps to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.