Impact
The vulnerability allows a remote attacker to perform an out‑of‑bounds read and disclose kernel memory contents. This out‑of‑bounds read (CWE‑125) can leak sensitive data stored in memory, leading to a compromise of confidentiality. The flaw does not grant code execution or broader system access, but the exposure of privileged information remains a serious risk.
Affected Systems
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 are affected by this issue.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a widespread or currently exploited flaw. Though the advisory states a remote attacker can disclose kernel memory, the exact remote attack vector is not fully detailed; the presence of APARs and service pack fixes confirms the issue is actionable.
OpenCVE Enrichment