CVE-2026-17168: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20 - Operational
Reboot the LPAR to complete the SP/FP update (AIX/VIOS remediation).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the VIOS 4.1.0.50 or 4.1.1.30 FP(s) migrate to the latest Postgres15 (additional required steps).
Event History
Frequently Asked Questions
Which systems should be prioritized for review?
Systems running IBM AIX or IBM PowerVM VIOS should be reviewed, as both are listed as affected software.
Does an attacker need prior access to exploit this issue?
Yes. Exploitation requires a remote attacker to be authenticated before they can attempt to execute arbitrary code.