CVE-2026-18832: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.3 TL02/TL03/TL04to a version that resolves this vulnerability.Fixed in 7.3 TL04SP2 - Upgrade
Upgrade
IBM AIX 7.3 TL02/TL03/TL04to a version that resolves this vulnerability.Fixed in 7.3 TL03SP3 - Upgrade
Upgrade
IBM AIX 7.3 TL02/TL03/TL04to a version that resolves this vulnerability.Fixed in 7.3 TL02SP5 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2 - Compensating control
Perform an LPAR reboot to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Which IBM products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.
Does exploitation require an attacker to have local access?
No. The issue is described as allowing a remote attacker to execute arbitrary code.