CVE-2026-17171: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Fixed in SP2 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Fixed in SP3 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Fixed in SP5 - Upgrade
Upgrade
IBM AIX 7.2 TL05to a version that resolves this vulnerability.Fixed in SP13 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308/14/2026 - Compensating control
If using nimsh secure to apply the patches, follow the special steps because the protocol between master and client is updated to be more secure.
- Compensating control
On AIX, Live Update can be used to avoid a reboot.
- Operational
Reboot the LPAR to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs respectively, perform the additional steps required to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Which products should be included in triage?
The affected software list includes IBM AIX and IBM PowerVM VIOS.