CVE-2026-17424: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2to a version that resolves this vulnerability.Patch SPKEY7.2.5 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956608 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956508 - Upgrade
Upgrade
IBM AIX 7.3to a version that resolves this vulnerability.Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Operational
Reboot the LPAR to complete the SP/FP update (an LPAR reboot is required to complete the SP/FP update).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the VIOS 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Which products are identified as affected?
The listed affected products are IBM AIX and IBM PowerVM VIOS.
Does the available information identify affected or fixed versions?
No affected or fixed version numbers are provided in the available data.