CVE-2026-17425: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AIX 7.2to a version that resolves this vulnerability.Patch SP13key_w_apar - Upgrade
Upgrade
AIX 7.3 TL02to a version that resolves this vulnerability.Patch SP05key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar7.3.2IJ5956508/14/2026SP05key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar7.3.3IJ5956408/14/2026SP03key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar7.3.4IJ59563 - Operational
For the SP/FP update, an LPAR reboot is required to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs.
- Operational
If applying AIX/VIOS patches using nimsh secure, take the special steps required because the protocol between master and client is updated to be more secure.
- Operational
On AIX, Live Update can be used to avoid a reboot.
Event History
Frequently Asked Questions
Is IBM PowerVM VIOS included in the affected software?
Yes. The listed affected software includes IBM AIX and IBM PowerVM VIOS.