Impact
The vulnerability is an integer underflow in the IPv4 IP‑options parser that allows a remote attacker to read sensitive data. The flaw can be triggered by carefully crafted packet options and results in disclosure of information that should be protected, potentially including configuration or content stored in memory. The weakness is classified as CWE‑125, an underflow condition that corrupts size calculations.
Affected Systems
IBM AIX releases 7.2 and 7.3 are vulnerable when they have not been updated to the Service Packs listed in the advisory. IBM PowerVM VIOS 4.1 is affected until the latest Fix Packs are applied. All earlier AIX 7.2.x and 7.3.x Service Packs, as well as VIOS 4.1.x releases, remain at risk until the recommended updates are installed.
Risk and Exploitability
The CVSS score of 9.4 indicates a high severity, and the vulnerability is exploitable from a remote network without authentication. EPSS is not available, but the lack of a KEV listing does not diminish the risk; an attacker with network access can send malicious IP‑options packets to trigger the underflow and extract data. IBM strongly recommends immediate installation of the specified SPs/FPs; failure to do so exposes systems to potential data exposure.
OpenCVE Enrichment