Impact
The vulnerability is a use‑after‑free flaw (CWE‑416) in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 that enables a remote attacker to trigger a denial of service. The flaw allows the attacker to cause the affected operating system or virtual I/O subsystem to crash, resulting in service interruption for users and applications that rely on those components. Because the vulnerability is exploitable remotely, an attacker only needs network access to the vulnerable system to destabilise its availability.
Affected Systems
IBM AIX 7.2 and 7.3 (including all releases prior to AIX 7.2 TL05 SP13, AIX 7.3 TL02 SP5, AIX 7.3 TL03 SP3, and AIX 7.3 TL04 SP2) and IBM PowerVM VIOS 4.1.0 4.1.0.50, VIOS 4.1.1 4.1.1.30, and VIOS 4.1.2 4.1.2.20 are affected. These platforms can be updated with the specified IBM AIX Service Packs or PowerVM VIOS Fix Packs that provide the required fixes.
Risk and Exploitability
The CVSS score of 7.4 classifies the issue as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so there may be no active exploitation observed yet. Nonetheless, because the flaw is remote and causes a denial of service, the likelihood of exploitation is considered moderate to high for environments where the affected systems are exposed to untrusted networks.
OpenCVE Enrichment