Impact
AIX 7.2, AIX 7.3, and PowerVM VIOS 4.1 are vulnerable to an out‑of‑bounds write that can be triggered by a remote attacker. The flaw is a memory corruption bug (CWE‑787) that allows the attacker to corrupt data structures and cause the operating system to halt or reset, resulting in a denial of service. No further detail is provided about the specific input or protocol that the attacker must use, so it is inferred that an external connection or network service could be the conduit for exploitation, but the exact vector is not stated.
Affected Systems
The affected vendors and product lines are IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS version 4.1. IBM lists cumulative Service Packs and Fix Packs for remediation: for AIX the recommended levels are TL04 SP2, TL03 SP3, TL02 SP5, and 7.2 TL05 SP13; for VIOS the equivalent levels are 4.1.2 FP 4.1.2.20, 4.1.1 FP 4.1.1.30, and 4.1.0 FP 4.1.0.50. The advisory states that the patches can be downloaded from Fix Central and applied to any earlier affected level, though an LPAR reboot is required to complete the update. On AIX, Live Update can avoid a reboot, and additional steps are required for VIOS to migrate to Postgres15 after applying the newer FPs.
Risk and Exploitability
The CVSS score of 7.5 indicates a high likelihood of a severe impact. The EPSS score of < 1% indicates a very low exploitation probability, but IBM recommends addressing the vulnerability immediately. The advisory does not list the vulnerability in the CISA KEV catalog, but the severity and the availability of an official fix suggest timely remediation is prudent. The advisability of the remediation steps is supported by the official APARs and the firm recommendation that the patches be applied without delay.
OpenCVE Enrichment