Impact
The vulnerability allows a remote attacker to trigger an out-of-bounds read within IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1. This condition can cause a denial of service by crashing affected processes or destabilizing the operating environment. The flaw is an out‑of‑bounds read as identified by CWE‑125.
Affected Systems
Affected systems are IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. IBM recommends applying the Service Pack levels listed in the advisory: AIX 7.3 TL04 SP2, AIX 7.3 TL03 SP3, AIX 7.3 TL02 SP5, AIX 7.2 TL05 SP13 for AIX, and VIOS Fix Pack levels 4.1.2 4.1.2.20, 4.1.1 4.1.1.30, and 4.1.0 4.1.0.50 for VIOS. These are cumulative and include fixes for all previously published vulnerabilities.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Attacks are likely remote; no public exploits are reported. The patching process requires an LPAR reboot, although AIX Live Update can avoid a reboot. The exploit would require the attacker to trigger the out‑of‑bounds read, leading to a service interruption.
OpenCVE Enrichment