CVE-2026-18716: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30 - Compensating control
For VIOS 4.1.0.50 and VIOS 4.1.1.30, follow the additional steps required to migrate to the latest Postgres15 after applying the corresponding VIOS FP (per the VIOS post-update instructions referenced for 4.1.0.50 and 4.1.1.30).
- Operational
Perform an LPAR reboot to complete the SP/FP update (AIX Service Pack / PowerVM VIOS Fix Pack update).
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker must be remote and authenticated to exploit this issue.
What impact can exploitation have?
Successful exploitation could allow an authenticated remote attacker to obtain sensitive information or cause a denial of service through an out-of-bounds read.
Which products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.