Impact
A remote attacker can trigger an unbounded recursion that crashes the operating system, resulting in a denial of service. The flaw resides in the kernel logic of IBM AIX 7.2 and 7.3 and in the PowerVM VIOS 4.1 platform. Once executed, the recursive call exhausts stack space, causing the system to halt or become unresponsive. No user privileges are required; a simple network request to the affected services is sufficient if the vulnerability is exploitable.
Affected Systems
The vulnerability affects IBM AIX 7.2 and 7.3, including all sub‑levels covered by the CPE tags, and IBM PowerVM VIOS 4.1.0, 4.1.1, and 4.1.2. IBM recommends applying the latest Service Packs for AIX (7.3 TL04 SP2, 7.3 TL03 SP3, 7.3 TL02 SP5, 7.2 TL05 SP13) and the matching Fix Packs for VIOS (4.1.2 4.1.2.20, 4.1.1 4.1.1.30, 4.1.0 4.1.0.50). These updates are cumulative and resolve all known security issues, including this denial of service flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating serious severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, so the exact likelihood of exploitation remains uncertain. Inferred from the description, the attack vector is remote network access; an attacker can invoke the vulnerable recursive call via a crafted request without authentication. The flaw does not require user‑level interaction and can be triggered remotely; after patching, a system reboot or a Live Update on AIX is needed to complete the remediation.
OpenCVE Enrichment