Impact
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 contain a vulnerability that permits an authenticated attacker to perform an out‑of‑bounds write. This flaw can be leveraged to expose sensitive information and to trigger a denial of service. The weakness is classified as CWE‑787 and is made available through IBM APARs and fix packs.
Affected Systems
Affected IBM platforms include AIX 7.2 TL05 SP13, AIX 7.3 TL04 SP2, TL03 SP3, and TL02 SP5, as well as PowerVM VIOS 4.1.0 (4.1.0.50), 4.1.1 (4.1.1.30), and 4.1.2 (4.1.2.20). The cumulative Service Packs and Fix Packs cover all prior security issues and can be applied using IBM Fix Central. Rebooting the LPAR is required unless a live update is used for AIX. VIOS updates also require additional steps to transition to Postgres15.
Risk and Exploitability
The CVSS score of 4.2 indicates moderately severe impact, while the EPSS score is not available and the vulnerability is not listed in CISA KEV, implying no current widespread exploitation. Attackers would need remote, authenticated access to the systems. Once privilege is obtained, the out‑of‑bounds write can be triggered, resulting in information leakage and service interruption. Prompt patching mitigates all known exploitation scenarios.
OpenCVE Enrichment