Impact
The flaw is a heap buffer overflow that can be triggered by a local user, allowing an attacker to stop services, crash the system, or otherwise disrupt availability. This weakness is identified as CWE‑787 and results in denial of service rather than code execution or data exposure.
Affected Systems
IBM AIX 7.2 and 7.3 systems, as well as IBM PowerVM VIOS 4.1 (including sub‑versions 4.1.0, 4.1.1, and 4.1.2), are impacted. The vulnerability is fixed by applying the designated Service Packs for AIX or the corresponding Fix Packs for VIOS, which provide the required APARs and also contain patches for earlier vulnerabilities.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack requires local privileges, so exploitation is limited to users who can run code on the affected host. A successful exploitation would lead to a service interruption or system reboot but does not enable remote code execution or data exfiltration.
OpenCVE Enrichment