Description
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
Published: 2026-08-28
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a format string flaw that permits a local attacker on IBM AIX 7.2 or 7.3, and on IBM PowerVM VIOS 4.1, to construct a malicious input that is processed by system components, allowing the attacker to rewrite memory and gain elevated privileges. This outcome compromises confidentiality, integrity, and availability of the affected system as the attacker effectively gains root or administrative control.

Affected Systems

AIX 7.2 and 7.3 in all releases, as well as PowerVM VIOS 4.1. IBM has mitigated the flaw in cumulative Service Packs and Fix Packs: AIX Service Packs SP2 for AIX 7.3 TL04, SP3 for TL03, SP5 for TL02, and SP13 for TL05; AIX 7.2 uses SP13. For VIOS, Fix Packs 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1, and 4.1.0.50 for VIOS 4.1.0.

Risk and Exploitability

The CVSS base score of 7.0 indicates a medium‑severity vulnerability and the exploit probability is unknown because EPSS data is not available. The flaw is not listed in CISA’s KEV catalog. Attackers must be local users with authenticated access who can supply crafted input to the vulnerable binary; no remote access is required. Consequently, the risk is significant for systems that run unauthenticated roles or are exposed in shared environments.

Generated by OpenCVE AI on August 28, 2026 at 23:27 UTC.

Remediation

Vendor Solution

A.  APARS IBM has assigned the following APARs to this problem: AIX LevelAPARAvailability  SPKEY7.2.5IJ5956608/14/2026SP13key_w_apar7.3.2IJ5956508/14/2026SP05key_w_apar7.3.3IJ5956408/14/2026SP03key_w_apar7.3.4IJ59563 08/14/2026SP02key_w_apar VIOS LevelAPARAvailability SPKEY4.1.0IJ5956508/14/20264.1.0.50key_w_apar4.1.1IJ5956408/14/20264.1.1.30key_w_apar4.1.2IJ5956308/14/20264.1.2.20key_w_apar B.  FIXES IBM strongly recommends addressing the vulnerability now.  AIX and VIOS fixes are available and can be downloaded from Fix Central: https://www.ibm.com/support/fixcentral  An LPAR reboot is required to complete the SP/FP update. On AIX, Live Update can be used to avoid a reboot.  IBM has assigned the following AIX Service Packs (SPs) and VIOS Fix Packs (FPs) as the remediation levels for the published vulnerabilities. AIX Level Service PackAIX 7.3 TL04SP2AIX 7.3 TL03SP3AIX 7.3 TL02SP5AIX 7.2 TL05 SP13 PowerVM VIOS LevelFix PackVIOS 4.1.2 4.1.2.20VIOS 4.1.1 4.1.1.30VIOS 4.1.0  4.1.0.50 Note: These SPs/FPs are cumulative and include fixes for all previously published AIX/VIOS security vulnerabilities. They can be applied on top of any earlier affected level of the TL . Note: To apply these patches using nimsh secure, special steps must be taken as the protocol between master and client is updated to be more secure. Please read this article: https://www.ibm.com/support/pages/node/7283157 Note: For VIOS 4.1.0 and VIOS 4.1.1, additional steps are required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs above. Instructions to do that can be found here:                             4.1.0.50 post-update instructions: https://www.ibm.com/support/pages/node/7283819           4.1.1.30 post-update instructions: https://www.ibm.com/support/pages/node/7283823


OpenCVE Recommended Actions

  • Apply the IBM Service Pack or Fix Pack corresponding to the product and level listed in the official advisory.
  • If the target is AIX, perform the update using Live Update to avoid an LPAR reboot; otherwise, reboot after applying the Service Pack.
  • For VIOS 4.1.0 or 4.1.1, after installing the latest Fix Pack, follow the IBM instructions to migrate to Postgres 15.
  • When using nimsh secure for the update, follow the protocol update steps described in the IBM article to ensure the update completes successfully.

Generated by OpenCVE AI on August 28, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
Title Vulnerabilities in IBM AIX and PowerVM VIOS
First Time appeared Ibm
Ibm aix
Ibm powervm Vios
Weaknesses CWE-134
CPEs cpe:2.3:a:ibm:aix:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aix:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aix:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aix:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_vios:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_vios:4.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aix
Ibm powervm Vios
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:43:04.351Z

Reserved: 2026-07-24T02:06:36.026Z

Link: CVE-2026-16821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:46.310

Modified: 2026-08-28T22:16:46.310

Link: CVE-2026-16821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:16Z

Weaknesses
  • CWE-134

    Use of Externally-Controlled Format String