CVE-2026-17165: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20 - Upgrade
Upgrade
IBM AIX 7.2to a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ59563 - Compensating control
When applying VIOS 4.1.0.50 or VIOS 4.1.1.30 FPs via nimsh secure, take the special steps noted in the instructions, as the protocol between master and client is updated to be more secure.
- Compensating control
On AIX, Live Update can be used to avoid a reboot (in addition to the required SP/FP update completion instructions).
- Operational
After applying the AIX service pack (SP) and/or VIOS fix pack (FP) updates, perform an LPAR reboot is required to complete the SP/FP update.
- Operational
Note for VIOS 4.1.0 and VIOS 4.1.1: additional steps are required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.