Impact
The vulnerability is an integer overflow in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 that allows a local attacker to read sensitive data or trigger a denial of service. The flaw is classified as CWE‑190. The impact is limited to systems where the attacker has local access and can exploit the overflow to leak confidential information or crash services.
Affected Systems
The affected products are IBM AIX 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1. IBM recommends applying specific APARs and Service Packs for AIX: SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02, and SP13 for AIX 7.2 TL05. For PowerVM VIOS the remediation levels are Fix Pack 4.1.2.20 for VIOS 4.1.2, 4.1.1.30 for VIOS 4.1.1, and 4.1.0.50 for VIOS 4.1.0. All updates are cumulative and can be applied on top of earlier affected levels.
Risk and Exploitability
The CVSS base score is 3.6, indicating low overall severity. EPSS data is unavailable and the vulnerability is not in CISA’s KEV catalog, suggesting lower exploitation probability. However, because the flaw requires local privilege, an attacker with local access could use the integer overflow to gain information or crash services. No public exploits are known, but the vulnerability should be mitigated promptly.
OpenCVE Enrichment