CVE-2026-19653: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper handling of memory page table configurations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 VIOS fix packs.
- Compensating control
If using AIX Live Update, it can be used to avoid a reboot (instead of performing the required LPAR reboot to complete the SP/FP update).
- Operational
Reboot the LPAR to complete the SP/FP update.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access to an affected PowerVM VIOS environment. The provided information does not indicate that remote exploitation is possible.
What impact can exploitation have?
Successful exploitation can cause a denial of service through improper handling of memory page table configurations. No information is provided about confidentiality or integrity impact.