Junglewise Threat Intelligence

CVE-2026-16980: IBM AIX and PowerVM VIOS symbolic link denial of service

CVE-2026-16980 · Severity: medium · CVSS 6.3 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a vulnerability in symbolic link validation that allows a local attacker to crash the system or cause service interruption. This could impact business continuity for organizations relying on these enterprise Unix-based operating systems and virtualization platforms.

Technical details

The vulnerability stems from improper validation of symbolic links in IBM AIX and PowerVM VIOS, allowing a local attacker to trigger a denial of service condition. The attack requires local access (unauthenticated or low-privilege) and no user interaction. By crafting malicious symbolic links, an attacker can cause the affected system to crash or become unresponsive. IBM has released security updates through Service Packs and Fix Packs to remediate this issue in supported releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with installation instructions

References

Related threats