IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Local DoS from Improper Symlink Validation
CVE-2026-16980 Published on August 20, 2026

Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper validation of symbolic links.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-16980 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2026-16980 has been classified to as an insecure temporary file vulnerability or weakness.


Products Associated with CVE-2026-16980

stack.watch emails you whenever new vulnerabilities are published in IBM Aix or IBM Powervm Vios. Just hit a watch button to start following.

 
 

Affected Versions

IBM AIX: IBM PowerVM VIOS: