Impact
The vulnerability is an out‑of‑bounds write that, when triggered by a remote attacker, can corrupt memory or overwrite control data. This leads to either remote code execution or a denial of service. The weakness is a classic buffer overflow (CWE‑787).
Affected Systems
IBM AIX 7.2, 7.3 (including all interim releases) and IBM PowerVM Virtual I/O Server (VIOS) 4.1 are affected. IBM recommends installing Service Pack 13 for AIX 7.2 TL05, Service Pack 2 for AIX 7.3 TL04, Service Pack 3 for AIX 7.3 TL03, Service Pack 5 for AIX 7.3 TL02, and the corresponding Fix Packs 4.1.0.50, 4.1.1.30, and 4.1.2.20 for VIOS. These cumulative updates address this and all prior vulnerabilities.
Risk and Exploitability
The CVSS score of 9.6 classifies this as Critical severity. No EPSS valuation is available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, as the description states a remote attacker can trigger the out‑of‑bounds write. Successful exploitation would grant full control over the affected system or cause system unavailability.
OpenCVE Enrichment