Impact
A stack‑based buffer overflow in IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1 allows a local attacker to execute arbitrary code. The flaw permits the attacker to overwrite return addresses on the stack, gain control of the execution flow, and run code with the privileges of the affected process. This leads to full compromise of the host where the vulnerable binaries are running, but does not provide a remote entry point.
Affected Systems
The vulnerability affects IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1.0 and 4.1.1. IBM has released cumulative service packs for AIX (SP2 for 7.3 TL04, SP3 for 7.3 TL03, SP5 for 7.3 TL02, and SP13 for 7.2 TL05) and fix packs for VIOS (4.1.0.50, 4.1.1.30, 4.1.2.20).
Risk and Exploitability
The CVSS score of 6.7 places the flaw in the medium range. No EPSS score is available and the issue is not listed in the CISA KEV catalog, indicating low to moderate exploit likelihood. Attackers must be local to the affected system; remote exploitation is not supported by the disclosed information. IBM strongly recommends applying the published APARs and cumulative service/ fix packs immediately to eliminate the stack overflow vulnerability.
OpenCVE Enrichment