IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7283858 |
|
History
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm vios
|
|
| CPEs | cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm vios
|
Wed, 19 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition. | |
| Title | Vulnerabilities in IBM AIX and PowerVM VIOS | |
| First Time appeared |
Ibm
Ibm aix Ibm powervm Vios |
|
| Weaknesses | CWE-367 | |
| CPEs | cpe:2.3:a:ibm:aix:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aix:7.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:aix:7.3.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aix:7.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_vios:4.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_vios:4.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aix Ibm powervm Vios |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-08-19T19:30:41.375Z
Updated: 2026-08-26T14:16:52.090Z
Reserved: 2026-07-24T02:56:39.108Z
Link: CVE-2026-16838
Updated: 2026-08-24T12:19:14.885Z
Status : Analyzed
Published: 2026-08-19T20:17:04.873
Modified: 2026-08-26T15:16:44.690
Link: CVE-2026-16838
No data.