Impact
A stack‑based buffer overflow in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 exposes the operating systems to arbitrary code execution. The flaw arises when a remote attacker can cause memory corruption that overwrites control information on the stack, allowing the attacker to run code with the privileges of the affected process. If successfully exploited, the attacker can compromise confidentiality, integrity and availability of the system and any services running on it.
Affected Systems
IBM AIX versions 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1 are affected. It is mitigated by applying the following updates: for AIX use Service Packs 7.3 TL04SP2, 7.3 TL03SP3, 7.3 TL02SP5 or 7.2 TL05 SP13; for VIOS use Fix Packs 4.1.2 4.1.2.20, 4.1.1 4.1.1.30 or 4.1.0 4.1.0.50. These packs are cumulative and can be stacked on top of earlier levels.
Risk and Exploitability
The CVSS score of 9.8 labels the vulnerability as critical. The description indicates a remote attacker can trigger the buffer overflow over the network. No EPSS score is published and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. Nonetheless, the high severity and remote nature mean the risk of compromise is significant without timely patching.
OpenCVE Enrichment