Impact
The vulnerability allows a remote attacker to induce a denial of service by causing the system to consume excessive resources. The flaw is an uncontrolled resource consumption weakness (CWE‑400). When triggered, one could exhaust CPU or memory, making the affected system unresponsive or causing service failures. The impact is a loss of availability for the affected workloads, with no direct confidentiality or integrity compromise.
Affected Systems
IBM AIX 7.2 and 7.3 are affected, as well as IBM PowerVM VIOS 4.1.0 through 4.1.2. The advisory recommends applying the following service packs: AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, and AIX 7.2 TL05 SP13. For VIOS, the Fix Packs are 4.1.2 4.1.2.20, 4.1.1 4.1.1.30, and 4.1.0 4.1.0.50. These levels are cumulative and include fixes for previously reported vulnerabilities.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog, so the exact likelihood of exploitation is unknown. The attack vector is remote, likely through the operating system’s resource management interfaces or virtual machine configuration processes. An attacker can trigger the DoS by sending crafted requests that consume resources beyond normal limits. After patching, a reboot of the LPAR is required, except when using AIX Live Update to apply the patch without reboot.
OpenCVE Enrichment