CVE-2026-18670: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.3 TL04SP2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.3 TL03SP3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.3 TL02SP5 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956608 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956508 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956408 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ59563 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956508/14/2026 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956408/14/2026 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956308/14/2026 - Operational
An LPAR reboot is required to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
What level of attacker access is required?
The issue is described as remotely exploitable; no local access requirement is stated.
Are affected versions or configurations identified?
No affected version ranges, configuration prerequisites, or default-configuration status are provided in the available data.
What is the potential security impact beyond service disruption?
The issue may also allow disclosure of sensitive information.