CVE-2026-18840: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2to a version that resolves this vulnerability.Fixed in SP13 - Upgrade
Upgrade
IBM AIX 7.3 TL04to a version that resolves this vulnerability.Fixed in SP2 - Upgrade
Upgrade
IBM AIX 7.3 TL03to a version that resolves this vulnerability.Fixed in SP3 - Upgrade
Upgrade
IBM AIX 7.3 TL02to a version that resolves this vulnerability.Fixed in SP5 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar - Compensating control
For VIOS 4.1.0 and 4.1.1: perform the additional required steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 Fix Packs.
- Operational
Reboot the LPAR after completing the SP/FP update to complete the update (an LPAR reboot is required to complete the SP/FP update).
- Operational
If using nimsh secure to apply these patches, follow the special steps noted in the provided IBM instructions because the protocol between master and client is updated to be more secure.
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
The issue is described as locally exploitable, so an attacker would need local access to an affected IBM AIX or IBM PowerVM VIOS system.