Impact
A NULL pointer dereference flaw in IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1 allows a remote attacker to trigger a denial‑of‑service condition by corrupting system memory or halting critical services. The vulnerability is characterized by CWE-476 and exhibits a high potential for causing system downtime or loss of availability, although it does not directly disclose or modify data. The impact is limited to service interruption rather than confidentiality or integrity compromise.
Affected Systems
The vulnerability affects IBM AIX releases 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. Specific remedial levels are defined by IBM through Service Packs for AIX (SP2 for 7.3 TL04, SP3 for TL03, SP5 for TL02, and SP13 for 7.2 TL05) and Fix Packs for VIOS (4.1.2.20 for 4.1.2, 4.1.1.30 for 4.1.1, and 4.1.0.50 for 4.1.0). All earlier affected tiers are superseded by these cumulative updates.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for this flaw. The EPSS score of <1% indicates that the likelihood of exploitation is very low, although not zero. The lack of an entry in the CISA KEV catalog corroborates that no widespread known attacks have been reported yet. Still, the remote nature of the vulnerability and its impact on availability warrant immediate attention. IBM recommends applying the latest Service Pack or Fix Pack to mitigate the risk; the requirement for an LPAR reboot or the use of Live Update on AIX is noted as a prerequisite for completing the patching process.
OpenCVE Enrichment