Impact
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain an out‑of‑bounds write condition that can be triggered by a remote attacker to cause a denial of service. The flaw arises from improper bounds checking during memory operations, which can corrupt internal state and lead to a crash. As a result, the vulnerable system becomes unavailable, disrupting any workloads or virtual machines running on the host.
Affected Systems
The affected products are IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1. The vulnerability covers any installation of AIX 7.2.0 or later, and any VIOS 4.1.0 or later. The specific Service Packs and Fix Packs that provide remediation are: for AIX 7.3 TL04SP2, 7.3 TL03SP3, 7.3 TL02SP5, and 7.2 TL05 SP13; for PowerVM VIOS 4.1.2 fix pack 4.1.2.20, 4.1.1 fix pack 4.1.1.30, and 4.1.0 fix pack 4.1.0.50.
Risk and Exploitability
The CVSS score of 6.5 denotes medium severity, and no EPSS data is available, indicating that exploitation probability has not been quantified. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation is known at this time. The likely attack vector is remote network access, as stated by the vendor, and a successful exploit would crash the AIX or VIOS system, halting all dependent services. Remediation requires applying the official Service Packs and Fix Packs to eliminate the memory corruption.
OpenCVE Enrichment