CVE-2026-17423: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Compensating control
After applying VIOS 4.1.0.50 or 4.1.1.30 FPs, perform the additional required steps to migrate to the latest Postgres15 for VIOS 4.1.0 and VIOS 4.1.1.
- Operational
Reboot the LPAR to complete the SP/FP update (LPAR reboot is required to complete the SP/FP update).
Event History
Frequently Asked Questions
Does exploitation require local access to the affected system?
No. The issue is described as exploitable by a remote attacker.
Which IBM products are identified as affected?
IBM AIX and IBM PowerVM VIOS are listed.
Does the available information identify affected versions or configuration prerequisites?
No affected version range or configuration prerequisite is provided in the available data.